Evidence dossier

CVE-2018-11776

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like…

Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 8.1. EPSS estimates 100.0% exploit likelihood as of Jul 26, 2026.

87.387.9Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

State
PUBLISHED
Published
Aug 22, 2018
Updated
Oct 21, 2025
Evidence coverage
98%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    apache

    Record text: Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

    Inspect raw assertion
    Field
    container
    Value
    Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Apache Struts Remote Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Apache Struts Remote Code Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.99% probability · 99.99th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999910000000; percentile 0.999850000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026

Exploit likelihood99.99%

FIRST EPSS · score date Jul 26, 2026 · 100th percentile · first observed Jul 27, 2026

SeverityCVSS 8.1

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

apacheOriginal assertion
Record text

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

Inspect raw assertion
Field
container
Value
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Apache Struts Remote Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Apache Struts Remote Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.99% probability · 99.99th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999910000000; percentile 0.999850000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
13Underlying assertions
8Canonical products
13Target assertions
0Constraint assertions

Grouped from 3 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

9 scope groups

apache · source assertedApache Software FoundationApache StrutsDirect source scope
Affected: 2.3 to 2.3.34Affected: 2.5 to 2.5.16
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "2.3 to 2.3.34"}, {"status": "affected", "version": "2.5 to 2.5.16"}]
NVD CPE · APPLICATIONapachestrutsVulnerable target · 2 assertions
Any version (unconstrained) (>= 2.0.4, < 2.3.35); Any version (unconstrained) (>= 2.5.0, < 2.5.17)Canonical identity product-9cd0052bcd831ad951c3a83f953006d77d3ff2278903b02b620cad9fb02389e0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 2.0.4; through excluding 2.3.35
    Match ID
    688f84a7-b698-4343-9f7b-fd68b2218035
  2. cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 2.5.0; through excluding 2.5.17
    Match ID
    0d66d46c-389b-4c37-9eee-6301774719fa
NVD CPE · APPLICATIONnetappactive_iq_unified_managerVulnerable target · 2 assertions
Any version (unconstrained) (>= 7.3); Any version (unconstrained) (>= 9.5)Canonical identity product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 7.3
    Match ID
    bd075607-09b7-493e-8611-66d041ffda62
  2. cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 9.5
    Match ID
    0cb28af5-5af0-4475-a7b6-12e1795ffdcb
NVD CPE · APPLICATIONnetapponcommand_insightVulnerable target · 1 assertions
Version not applicableCanonical identity product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f1be6c1f-2565-4e97-92aa-16563e5660a5
NVD CPE · APPLICATIONnetapponcommand_workflow_automationVulnerable target · 1 assertions
Version not applicableCanonical identity product-afac260708bb4bb1a51e28ce6b95f0356203366f8c8ffd2c790c3109033fc4fdLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5735e553-9731-4aac-bcff-989377f817b3
NVD CPE · APPLICATIONnetappsnapcenterVulnerable target · 1 assertions
Version not applicableCanonical identity product-72194eb69952d9519f325006ffebfb4101503889dc70b262bb3ce2ae0ce452a2Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bdfb1169-41a0-4a86-8e4f-fda9730b1e94
NVD CPE · APPLICATIONoraclecommunications_policy_managementVulnerable target · 1 assertions
Any version (unconstrained) (< 12.5.0)Canonical identity product-d355b11887e16a673439034955f56c1713687fe0ddcca9e46745eb07d77aae8bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:communications_policy_management:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 12.5.0
    Match ID
    0e8af73e-8ac6-4f65-a6f0-dbb2cc7a613f
NVD CPE · APPLICATIONoracleenterprise_manager_base_platformVulnerable target · 2 assertions
Version 13.3.0.0; Version 13.4.0.0Canonical identity product-3c4aa68ebd05c096ade3c96e36c96721c931455c324c5da69df15a2fee41a8fdLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7582b307-3899-4bbb-b868-bc912a4d0109
  2. cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d26f3e23-f1a9-45e7-9e5f-0c0a24ee3783
NVD CPE · APPLICATIONoraclemysql_enterprise_monitorVulnerable target · 3 assertions
Any version (unconstrained) (<= 3.4.9.4237); Any version (unconstrained) (>= 4.0.0, <= 4.0.6.5281); Any version (unconstrained) (>= 8.0.0, <= 8.0.2.8191)Canonical identity product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213facLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 4.0.0; through including 4.0.6.5281
    Match ID
    ef71d94f-efc5-4390-a380-ac0e5db05516
  2. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    through including 3.4.9.4237
    Match ID
    8a94b32d-6b5f-4e42-8345-4f9126a89435
  3. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 8.0.0; through including 8.0.2.8191
    Match ID
    33efaf19-a639-47ad-9cdc-d174c91f0f00

Affected-product evidence

Accepted scope and product mapping

8 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-3c4aa68ebd05c096ade3c96e36c96721c931455c324c5da69df15a2fee41a8fd

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3e0fc636-7ac4-4c0a-b4db-9fc0c2b55a965163ac08-d307-465c-b813-4dbb7c436905
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213fac

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2116bf91-b441-4263-9c93-51f69fe351b85f46fe8c-4205-42ee-9dd1-5b42448cef6ec8b531f0-41cc-4b20-a409-880221a5c1ad
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2ce4bb6f-ec72-45d0-a682-807edb9fefc7
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-72194eb69952d9519f325006ffebfb4101503889dc70b262bb3ce2ae0ce452a2

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
719976d7-febe-44e0-94b5-4a43e74bde1f
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2034073e-349a-4519-a61e-c50ff373b800598e24a3-19d7-463a-aa3f-b589a6fc56ba
Mapping establishedEvidence supported

vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-9cd0052bcd831ad951c3a83f953006d77d3ff2278903b02b620cad9fb02389e0

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ace5c62f-1253-453f-b1e2-a77b3ae4cc2ff286dffd-daa5-4a6f-a7c6-26cb5ae53711
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-afac260708bb4bb1a51e28ce6b95f0356203366f8c8ffd2c790c3109033fc4fd

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
96f53666-8d72-4b76-80ac-a542353af37c
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-d355b11887e16a673439034955f56c1713687fe0ddcca9e46745eb07d77aae8b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c56dbbf3-994c-487b-8b06-aa38b75217f9
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3ec0b982-a57e-43e6-9ddb-3f34b1d8f5d4

Assessments

CVSS by origin

8.1
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:M/Au:N/C:C/I:C/A:C
8.1
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
8.1
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.1Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.1
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.