What is Apache Struts?
Apache Struts 2 is a Java web application framework. It maps incoming HTTP requests onto action classes, binds request parameters to Java objects, and renders the result through a template. Struts has been a default choice for Java shops building internal and public web applications since the mid 2000s, which is why its flaws have outsized consequences: the framework sits underneath banking portals, government services, and enterprise back offices rather than being a product anyone deploys on its own. Struts uses OGNL, the Object-Graph Navigation Language, to evaluate expressions when binding parameters and rendering views. OGNL can reach arbitrary Java objects and call arbitrary methods, so any place where attacker input reaches an OGNL evaluation is a candidate for remote code execution. Most of the famous Struts CVEs, this one included, are variations on that theme.
Overview
CVE-2016-3081, tracked by Apache as S2-032, is remote code execution through the method: prefix. Struts supports an optional feature called Dynamic Method Invocation, which lets the HTTP request name which method of the action class should run, expressed as a method:name parameter or as part of the URL. The framework passed that value into an OGNL evaluation without constraining it, so an attacker could supply an expression instead of a method name and have it evaluated server-side with the privileges of the application server.
The outcome is full command execution as the servlet container user: spawning a shell, writing a JSP webshell into the application directory, or reading application secrets and database credentials. Nothing about the target application has to be known in advance beyond a reachable Struts action URL, which is typically any .action or .do endpoint.
The feature is the precondition. Dynamic Method Invocation is controlled by struts.enable.DynamicMethodInvocation, and in the affected releases it defaulted to enabled for backward compatibility with Struts 1 style applications. That default is what turned a niche feature into a mass-exploitation event. NVD scores the CVE 8.1 High with attack complexity High (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H); the complexity rating reflects the configuration dependency rather than any difficulty in the exploit itself, which is a single HTTP request.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| Apache Struts 2.3.20 branch | 2.3.20 through 2.3.20.2 | 2.3.20.3 |
| Apache Struts 2.3.24 branch | 2.3.24 through 2.3.24.2 | 2.3.24.3 |
| Apache Struts 2.3.28 branch | 2.3.28 | 2.3.28.1 |
| Any Struts 2 release with DynamicMethodInvocation disabled | not exploitable | configuration change is sufficient |
Sources disagree slightly on the boundary. The Apache bulletin states 2.3.20 through 2.3.28 excluding 2.3.20.3 and 2.3.24.3, while the NVD text says before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1. The .2 releases were an initial attempt and the .3 releases are the ones Apache ultimately recommends; treat 2.3.20.3, 2.3.24.3, and 2.3.28.1 as the safe targets. Applications on Struts 1 are a different codebase and are not affected by this CVE.
Technical Details
The CWE assignment is CWE-77, command injection: untrusted input is placed into something the system then interprets as a command. Here the interpreter is OGNL rather than a shell. Struts' DefaultActionMapper parsed the method: prefix out of the request and handed the remainder to the action invocation machinery, where it reached an OGNL expression evaluation. The CVE record describes the issue as related to chained expressions, meaning the attacker strings OGNL operations together to reach the Java runtime, typically via @java.lang.Runtime@getRuntime().exec(...) or a reflective equivalent, with preparatory expressions used to clear the OGNL sandbox flags that would otherwise block member access.
Attack characteristics: unauthenticated, no user interaction, one request, and no memory corruption, so the exploit is reliable and portable across operating systems and application servers. The only prerequisites are that Dynamic Method Invocation is on and that the attacker can reach any Struts action endpoint. The same DynamicMethodInvocation setting was implicated weeks later in S2-033 (CVE-2016-3087), remote code execution through the REST plugin with the ! operator, which is why Apache's guidance moved from patching to switching the feature off entirely and eventually to removing it.
Discovery
Apache credits Nike Zheng with reporting the vulnerability. Apache published S2-032 with the fixed releases on 2016-04-26, and working exploit code was in public circulation within a day; Rapid7's Metasploit module exploit/multi/http/struts_dmi_exec carries a disclosure date of 2016-04-27. There was effectively no grace period between disclosure and weaponisation.
Exploitation Context
S2-032 became a staple of opportunistic internet-wide scanning through 2016 and 2017, in the same wave that later carried CVE-2017-5638, the Struts flaw used against Equifax. The two are frequently conflated: Equifax was S2-045, not S2-032. Public exploits for this CVE exist in Metasploit, Exploit-DB, Packet Storm, and numerous standalone scripts, and generic Struts OGNL scanners test several of these payloads in one pass.
CISA added the CVE to the KEV catalog on 2026-10-08, which is the authoritative confirmation of exploitation; the entry names no threat actor and marks the CVE as not known to be used in ransomware campaigns. Public reporting from the 2016 period documents mass scanning and public exploit availability rather than named campaigns, so attribution for this specific CVE should be treated as unestablished. Exposure counts are unreliable because a Struts application does not advertise its framework version, and the vulnerable condition depends on a configuration setting that cannot be read from outside; the realistic risk population is unmaintained internal Java applications and vendor appliances that embedded a 2.3.x Struts and were never rebuilt.
Remediation
- Upgrade Struts. Move to a currently supported release rather than to the 2016 patch level; the whole 2.3 line is end of life and carries many later OGNL RCEs including S2-045, S2-046, and S2-061.
- Disable Dynamic Method Invocation. Set
struts.enable.DynamicMethodInvocationtofalseinstruts.xmlorstruts.properties. This removes the precondition for this CVE and for S2-033, and in most modern applications nothing depends on the feature. - If the setting must stay on because a legacy application needs it, Apache's alternative workaround is to implement your own
ActionMapperbased on the fixed Struts source, restricting what themethod:prefix accepts. - Find the embedded copies. Search deployed WAR and EAR files for
struts2-core-*.jarto identify the real version; a dependency manifest in source control often does not match what is running in production. - Put a WAF rule or reverse proxy filter in front of the application to reject requests containing
method:prefixes and OGNL markers such as@java.lang.Runtime@. Treat this as a stopgap: OGNL payload encodings are varied and signature evasion is well documented. - Review for compromise before declaring the issue closed. Check application and access logs for requests containing
method:with expression syntax, inspect the webroot and temporary directories for unexpected JSP files, and review the application server account for unexpected scheduled tasks, outbound connections, or cryptomining processes. A 2016 vulnerability patched in 2026 may have been exploited years ago. - Federal civilian agencies must remediate by 2026-10-11 under BOD 26-04 and perform the forensic triage the directive requires.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2016-3081 |
| Vendor / Product | Apache — Struts |
| NVD Published | 2016-04-26 |
| NVD Last Modified | 2026-10-08 |
| CVSS 3.1 Score | 8.1 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Severity | HIGH |
| CWE | CWE-77 find similar ↗ |
| CISA KEV Added | 2026-10-08 |
| CISA KEV Deadline | 2026-10-11 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2016-04-26 | Apache publishes security bulletin S2-032 and the CVE-2016-3081 record is released |
| 2016-04-27 | Public exploit code appears; Metasploit module struts_dmi_exec is disclosed |
| 2026-10-08 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2026-10-11 | CISA BOD 26-04 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD - CVE-2016-3081 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |
| Apache Struts Security Bulletin S2-032 - Remote Code Execution via method: Prefix | Vendor Advisory |
| Apache Struts Security Bulletin S2-033 - RCE via REST Plugin when Dynamic Method Invocation is Enabled | Vendor Advisory |
| Rapid7 - Apache Struts Dynamic Method Invocation Remote Code Execution Metasploit Module | Security Research |
| Debian Security Tracker - CVE-2016-3081 | Vulnerability Database |
| CIRCL Vulnerability Lookup - CVE-2016-3081 | Vulnerability Database |