EIP-2026-103848
PRE-CVEApache Struts 2 - Skill Name Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103848. PoCs published by kxlzx.
AI-analyzed exploit summary This is a functional OGNL injection payload for Apache Struts2 that exploits insufficient input sanitization to execute arbitrary code. The payload manipulates Struts2's OGNL context to disable security restrictions and execute a response writer to print a message, demonstrating remote code execution.
Description
Apache Struts 2 - Skill Name Remote Code Execution
Exploits (1)
This is a functional OGNL injection payload for Apache Struts2 that exploits insufficient input sanitization to execute arbitrary code. The payload manipulates Struts2's OGNL context to disable security restrictions and execute a response writer to print a message, demonstrating remote code execution.