Apache Struts Command Injection Vulnerability
TL;DR 📌
- Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
- Highest CVSS: 8.1 (High).
- Listed in CISA KEV (2026-10-08) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2016-3081.
What it is
CVE-2016-3081 is a command injection vulnerability in Apache Struts, triggered through the method: prefix when Dynamic Method Invocation (DMI) is enabled. The flaw sits in how Struts resolves chained OGNL expressions passed via this prefix, allowing attacker-supplied input to be evaluated as code rather than treated as a plain parameter value.
The affected releases are Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28. The CVSS vector (AV:N/AC:H/PR:N/UI:N) indicates this is reachable over the network with no authentication and no user interaction required, though attack complexity is rated high. Successful exploitation yields high impact across confidentiality, integrity and availability — consistent with arbitrary code execution on the application server.
The precondition is that Dynamic Method Invocation must be enabled on the affected Struts configuration; this is a feature flag rather than a default that’s always on, so exposure depends on how the application was configured.
This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added 2026-10-08, meaning it is known to be exploited.
What to do
- Disable Dynamic Method Invocation. Set
struts.enable.DynamicMethodInvocationtofalseinstruts.properties(or the equivalent configuration mechanism) — this removes the exploitation path even if the underlying library version is unchanged. - Identify any Struts deployments running 2.3.19–2.3.20.2, 2.3.21–2.3.24.1, or 2.3.25–2.3.28 and confirm whether DMI is enabled in their configuration.
- The advisory does not list a fixed release; consult the Apache Struts advisory directly for the recommended upgrade path for your specific version line.
- Given this is in CISA KEV, prioritise remediation and treat it as requiring action within whatever timeframe your organisation applies to KEV entries.
- Review application logs and WAF rules for requests containing
method:prefixes with chained expressions, as a detection measure while remediation is in progress.
For leadership 🧭
Executive summary. Any Struts application in the 2.3.19–2.3.28 range with Dynamic Method Invocation enabled can be taken over remotely without login, and this is now flagged as actively exploited in CISA’s KEV catalogue. Because no patched version is listed, the fastest fix is a one-line configuration change rather than waiting for an upgrade path.
Why it matters:
- Exploitation requires no authentication and no user interaction — any internet-reachable Struts 2.3.19-2.3.28 endpoint with DMI enabled is a direct path to the application server.
- A successful attack gives full read/write/execute impact, consistent with arbitrary code execution on the host running the Struts application.
- The exposure hinges entirely on one configuration flag (DMI) rather than the Struts version itself, so two identical deployments can have very different risk depending on settings.
- Listing in CISA KEV means this is confirmed as exploited in the wild, raising the urgency above a typical unpatched-library finding.
Now / Next / Later:
- Now: Set struts.enable.DynamicMethodInvocation to false in struts.properties (or your equivalent config) on every Struts instance in the 2.3.19–2.3.28 range to close the exploitation path immediately.
- Next: Inventory all Struts deployments running 2.3.19–2.3.20.2, 2.3.21–2.3.24.1 or 2.3.25–2.3.28, confirm DMI status on each, and check Apache’s own advisory for a version-specific upgrade recommendation since none is listed here.
- Later: Add method: prefix with chained-expression patterns to WAF rules and log monitoring as a standing detection, and make DMI-disabled the default configuration baseline for any future Struts deployment.