Apache Struts - RCE (CVE-2018-11776)
Description
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
psychologyCrowdSec Analysis
CVE-2018-11776 is a remote code execution vulnerability in Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16, which can be exploited when certain namespace configurations are present. Attackers can leverage this flaw to execute arbitrary code on affected servers without authentication, potentially leading to full system compromise. This vulnerability is particularly dangerous for web applications using the Convention Plugin or misconfigured namespaces, making it a prime target for remote attacks.
CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.
CrowdSec network data shows that most actors exploiting CVE-2018-11776 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2018-11776. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.
Attackers exploit this vulnerability by sending specially crafted requests with OGNL expressions embedded in the URL path, often targeting endpoints ending in .action such as /help.action or /actionChain1.action, to achieve remote code execution on vulnerable Apache Struts2 servers.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2018-08-22 |
| CISA KEV | 2021-11-03 |
| CISA Remediation Deadline | 2022-05-03 |
| Rule Released | 2026-06-24 |
| CrowdSec First Seen | 2026-06-25 |
Remediation & Protection
External References
- https://github.com/hook-s3c/CVE-2018-11776-Python-PoC
- https://security.netapp.com/advisory/ntap-20181018-0002/
- http://www.securitytracker.com/id/1041547
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776
- http://www.securitytracker.com/id/1041888
- http://www.securityfocus.com/bid/105125
- http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://lgtm.com/blog/apache_struts_CVE-2018-11776
- https://cwiki.apache.org/confluence/display/WW/S2-057
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-11776-5072787.html
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
- https://www.oracle.com/security-alerts/cpujul2020.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012
- https://security.netapp.com/advisory/ntap-20180822-0001/
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-11776.yaml