# CVE-2018-11776: Apache Struts - RCE

> Live exploitation tracking for CVE-2018-11776 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2018-11776

## Key facts

- **Exploitation phase:** Background Noise. Continuous low-level scanning or exploitation attempts are observed, mostly opportunistic and automated.
- **CVSS score:** 8.1
- **Public exploit available:** Yes
- **Affected products:** Apache Struts
- **Weaknesses:** CWE-94 (Improper Control of Generation of Code ('Code Injection'))
- **Tags:** java, web_application

## Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

## CrowdSec analysis

[CVE-2018-11776](https://euvd.enisa.europa.eu/vulnerability/CVE-2018-11776) is a remote code execution vulnerability in Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16, which can be exploited when certain namespace configurations are present. Attackers can leverage this flaw to execute arbitrary code on affected servers without authentication, potentially leading to full system compromise. This vulnerability is particularly dangerous for web applications using the Convention Plugin or misconfigured namespaces, making it a prime target for remote attacks.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network data shows that most actors exploiting CVE-2018-11776 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature.
Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2018-11776. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit this vulnerability by sending specially crafted requests with OGNL expressions embedded in the URL path, often targeting endpoints ending in `.action` such as `/help.action` or `/actionChain1.action`, to achieve remote code execution on vulnerable Apache Struts2 servers.

## Timeline

- 2018-08-22: CVE Published. CVE-2018-11776 is published to NVD.
- 2021-11-03: CISA KEV. CVE-2018-11776 is added to the Known Exploited Vulnerabilities catalog by CISA.
- 2022-05-03: CISA Remediation Deadline. Expiration of the CISA remediation deadline as described in [BOD 22-01](https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities).
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2018-11776 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2018-11776 for the first time.

## References

- https://github.com/hook-s3c/CVE-2018-11776-Python-PoC
- https://security.netapp.com/advisory/ntap-20181018-0002/
- http://www.securitytracker.com/id/1041547
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776
- http://www.securitytracker.com/id/1041888
- http://www.securityfocus.com/bid/105125
- http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://lgtm.com/blog/apache_struts_CVE-2018-11776
- https://cwiki.apache.org/confluence/display/WW/S2-057
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-11776-5072787.html
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
- https://www.oracle.com/security-alerts/cpujul2020.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012
- https://security.netapp.com/advisory/ntap-20180822-0001/
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-11776.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2018-11776) follows observed exploitation activity for CVE-2018-11776. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
