August 3, 2026

CVE Watchtower


← Back to CVE List

CVE-2018-11776NVD

Vulnerability Summary

Apache Struts contains a Remote Code Execution when using results with no namespace and it's upper actions have no or wildcard namespace. The same flaw exists when using a url tag with no value, action set, and it's upper actions have no or wildcard namespace.
Severity Level
HIGH(8.1)
Published Date
Aug 22, 2018
Last Modified
Oct 22, 2025
Exploitation Status
ACTIVE
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A
CVSS v3.0 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

External References