← Vulnerability feed

Vulnerability record · CVE-2018-11776 · published 22 August 2018

CVE-2018-11776: Apache Struts namespace handling flaw enables remote code execution

Apache · Struts

Apache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are used without a namespace while the upper package has no or a wildcard namespace. This is a well-known, widely exploited Struts flaw that allows unauthenticated attackers to run code on the server.

8.1 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 100% · top 0.1%
8.1CVSS 3.1 base score, v2 9.3
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
8Affected product versions listed by NVD
39References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw allows unauthenticated remote code execution, is listed in CISA KEV, has public exploits, and shows an EPSS probability near 1.0.

What it is

Apache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are used without a namespace while the upper package has no or a wildcard namespace. This is a well-known, widely exploited Struts flaw that allows unauthenticated attackers to run code on the server.

Impact

An attacker can execute arbitrary code with the privileges of the Struts application, leading to full server compromise, data theft, or use as a foothold for lateral movement.

Attack surface

Reachable over the network via HTTP requests to a vulnerable Struts application; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).

Exploitation

Exploitation is confirmed: CVE-2018-11776 is in CISA KEV (added 2021-11-03) and has public exploit references (ExploitDB, GitHub PoC) with an EPSS 30-day probability of 0.99991.

What to do

  • Upgrade Apache Struts to a fixed version (2.3.35 or later in the 2.3 line, or 2.5.17 or later in the 2.5 line) as directed by the vendor.
  • If immediate upgrade is not possible, disable alwaysSelectFullNamespace or ensure all result and url tag usages specify explicit namespaces and avoid wildcard or empty namespaces in upper packages.
  • Apply vendor patches for affected Oracle, NetApp, and other products that bundle Struts.
  • Restrict network access to Struts applications to trusted sources where feasible.
  • Monitor for and block known exploit patterns targeting Struts namespace handling.

Detection

  • Inspect HTTP requests for suspicious OGNL expressions or namespace manipulation in URLs targeting Struts actions.
  • Monitor application and web server logs for unexpected command execution, outbound connections, or child processes spawned by the Java process.
  • Use IDS/IPS signatures or WAF rules that detect CVE-2018-11776 exploit attempts.
  • Audit deployed Struts versions and configurations to identify instances with alwaysSelectFullNamespace enabled and vulnerable namespace setups.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-11776 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apache Struts Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-005.txt Broken LinkMailing ListThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-11776-5072787.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html PatchThird Party Advisory
http://www.securityfocus.com/bid/105125 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1041547 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1041888 Broken LinkThird Party AdvisoryVDB Entry
https://cwiki.apache.org/confluence/display/WW/S2-057 Issue TrackingThird Party Advisory
https://github.com/hook-s3c/CVE-2018-11776-Python-PoC ExploitThird Party Advisory
https://lgtm.com/blog/apache_struts_CVE-2018-11776 ExploitThird Party Advisory
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org% Mailing List
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012 Third Party Advisory
https://security.netapp.com/advisory/ntap-20180822-0001/ Third Party Advisory
https://security.netapp.com/advisory/ntap-20181018-0002/ Third Party Advisory
https://www.exploit-db.com/exploits/45260/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/45262/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/45367/ ExploitThird Party AdvisoryVDB Entry
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchThird Party Advisory
http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-005.txt Broken LinkMailing ListThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-11776-5072787.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html PatchThird Party Advisory
http://www.securityfocus.com/bid/105125 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1041547 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1041888 Broken LinkThird Party AdvisoryVDB Entry
https://cwiki.apache.org/confluence/display/WW/S2-057 Issue TrackingThird Party Advisory
https://github.com/hook-s3c/CVE-2018-11776-Python-PoC ExploitThird Party Advisory
https://lgtm.com/blog/apache_struts_CVE-2018-11776 ExploitThird Party Advisory
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org% Mailing List
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012 Third Party Advisory
https://security.netapp.com/advisory/ntap-20180822-0001/ Third Party Advisory
https://security.netapp.com/advisory/ntap-20181018-0002/ Third Party Advisory
https://www.exploit-db.com/exploits/45260/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/45262/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/45367/ ExploitThird Party AdvisoryVDB Entry
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776 US Government Resource

Track CVE-2018-11776 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.8CVE-2017-9791Apache Struts 1 plugin input validation flaw enables remote code executionThe Struts 1 plugin in Apache Struts 2.1.x and 2.3.x may allow remote code execution when a malicious field value is passed in a raw message to the A…KEVEPSS 99%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2013-2251Apache Struts 2 OGNL injection enables remote code executionApache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to…KEVEPSS 100%analysed9.8CVE-2012-0391Apache Struts ExceptionDelegator OGNL injection enables remote code executionApache Struts before 2.2.3.1 evaluates parameter values as OGNL expressions in the ExceptionDelegator component during exception handling for mismatc…KEVEPSS 76%analysed

Source: NIST National Vulnerability Database (record CVE-2018-11776), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.