CVE-2016-3081 — Apache Struts Command Injection Vulnerability

CVE-2016-3081

Apache Struts 2 (S2-032) - OGNL Code Execution via the method: Prefix

What is Apache Struts?

Apache Struts 2 is a Java web application framework. It maps incoming HTTP requests onto action classes, binds request parameters to Java objects, and renders the result through a template. Struts has been a default choice for Java shops building internal and public web applications since the mid 2000s, which is why its flaws have outsized consequences: the framework sits underneath banking portals, government services, and enterprise back offices rather than being a product anyone deploys on its own. Struts uses OGNL, the Object-Graph Navigation Language, to evaluate expressions when binding parameters and rendering views. OGNL can reach arbitrary Java objects and call arbitrary methods, so any place where attacker input reaches an OGNL evaluation is a candidate for remote code execution. Most of the famous Struts CVEs, this one included, are variations on that theme.

Overview

CVE-2016-3081, tracked by Apache as S2-032, is remote code execution through the method: prefix. Struts supports an optional feature called Dynamic Method Invocation, which lets the HTTP request name which method of the action class should run, expressed as a method:name parameter or as part of the URL. The framework passed that value into an OGNL evaluation without constraining it, so an attacker could supply an expression instead of a method name and have it evaluated server-side with the privileges of the application server.

The outcome is full command execution as the servlet container user: spawning a shell, writing a JSP webshell into the application directory, or reading application secrets and database credentials. Nothing about the target application has to be known in advance beyond a reachable Struts action URL, which is typically any .action or .do endpoint.

The feature is the precondition. Dynamic Method Invocation is controlled by struts.enable.DynamicMethodInvocation, and in the affected releases it defaulted to enabled for backward compatibility with Struts 1 style applications. That default is what turned a niche feature into a mass-exploitation event. NVD scores the CVE 8.1 High with attack complexity High (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H); the complexity rating reflects the configuration dependency rather than any difficulty in the exploit itself, which is a single HTTP request.

Affected Versions

Product Vulnerable Fixed
Apache Struts 2.3.20 branch 2.3.20 through 2.3.20.2 2.3.20.3
Apache Struts 2.3.24 branch 2.3.24 through 2.3.24.2 2.3.24.3
Apache Struts 2.3.28 branch 2.3.28 2.3.28.1
Any Struts 2 release with DynamicMethodInvocation disabled not exploitable configuration change is sufficient

Sources disagree slightly on the boundary. The Apache bulletin states 2.3.20 through 2.3.28 excluding 2.3.20.3 and 2.3.24.3, while the NVD text says before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1. The .2 releases were an initial attempt and the .3 releases are the ones Apache ultimately recommends; treat 2.3.20.3, 2.3.24.3, and 2.3.28.1 as the safe targets. Applications on Struts 1 are a different codebase and are not affected by this CVE.

Technical Details

The CWE assignment is CWE-77, command injection: untrusted input is placed into something the system then interprets as a command. Here the interpreter is OGNL rather than a shell. Struts' DefaultActionMapper parsed the method: prefix out of the request and handed the remainder to the action invocation machinery, where it reached an OGNL expression evaluation. The CVE record describes the issue as related to chained expressions, meaning the attacker strings OGNL operations together to reach the Java runtime, typically via @java.lang.Runtime@getRuntime().exec(...) or a reflective equivalent, with preparatory expressions used to clear the OGNL sandbox flags that would otherwise block member access.

Attack characteristics: unauthenticated, no user interaction, one request, and no memory corruption, so the exploit is reliable and portable across operating systems and application servers. The only prerequisites are that Dynamic Method Invocation is on and that the attacker can reach any Struts action endpoint. The same DynamicMethodInvocation setting was implicated weeks later in S2-033 (CVE-2016-3087), remote code execution through the REST plugin with the ! operator, which is why Apache's guidance moved from patching to switching the feature off entirely and eventually to removing it.

Discovery

Apache credits Nike Zheng with reporting the vulnerability. Apache published S2-032 with the fixed releases on 2016-04-26, and working exploit code was in public circulation within a day; Rapid7's Metasploit module exploit/multi/http/struts_dmi_exec carries a disclosure date of 2016-04-27. There was effectively no grace period between disclosure and weaponisation.

Exploitation Context

S2-032 became a staple of opportunistic internet-wide scanning through 2016 and 2017, in the same wave that later carried CVE-2017-5638, the Struts flaw used against Equifax. The two are frequently conflated: Equifax was S2-045, not S2-032. Public exploits for this CVE exist in Metasploit, Exploit-DB, Packet Storm, and numerous standalone scripts, and generic Struts OGNL scanners test several of these payloads in one pass.

CISA added the CVE to the KEV catalog on 2026-10-08, which is the authoritative confirmation of exploitation; the entry names no threat actor and marks the CVE as not known to be used in ransomware campaigns. Public reporting from the 2016 period documents mass scanning and public exploit availability rather than named campaigns, so attribution for this specific CVE should be treated as unestablished. Exposure counts are unreliable because a Struts application does not advertise its framework version, and the vulnerable condition depends on a configuration setting that cannot be read from outside; the realistic risk population is unmaintained internal Java applications and vendor appliances that embedded a 2.3.x Struts and were never rebuilt.

Remediation

  1. Upgrade Struts. Move to a currently supported release rather than to the 2016 patch level; the whole 2.3 line is end of life and carries many later OGNL RCEs including S2-045, S2-046, and S2-061.
  2. Disable Dynamic Method Invocation. Set struts.enable.DynamicMethodInvocation to false in struts.xml or struts.properties. This removes the precondition for this CVE and for S2-033, and in most modern applications nothing depends on the feature.
  3. If the setting must stay on because a legacy application needs it, Apache's alternative workaround is to implement your own ActionMapper based on the fixed Struts source, restricting what the method: prefix accepts.
  4. Find the embedded copies. Search deployed WAR and EAR files for struts2-core-*.jar to identify the real version; a dependency manifest in source control often does not match what is running in production.
  5. Put a WAF rule or reverse proxy filter in front of the application to reject requests containing method: prefixes and OGNL markers such as @java.lang.Runtime@. Treat this as a stopgap: OGNL payload encodings are varied and signature evasion is well documented.
  6. Review for compromise before declaring the issue closed. Check application and access logs for requests containing method: with expression syntax, inspect the webroot and temporary directories for unexpected JSP files, and review the application server account for unexpected scheduled tasks, outbound connections, or cryptomining processes. A 2016 vulnerability patched in 2026 may have been exploited years ago.
  7. Federal civilian agencies must remediate by 2026-10-11 under BOD 26-04 and perform the forensic triage the directive requires.

Key Details

PropertyValue
CVE ID CVE-2016-3081
Vendor / Product Apache — Struts
NVD Published2016-04-26
NVD Last Modified2026-10-08
CVSS 3.1 Score8.1
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
SeverityHIGH
CWE CWE-77 find similar ↗
CISA KEV Added2026-10-08
CISA KEV Deadline2026-10-11
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2026-10-11. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

DateEvent
2016-04-26Apache publishes security bulletin S2-032 and the CVE-2016-3081 record is released
2016-04-27Public exploit code appears; Metasploit module struts_dmi_exec is disclosed
2026-10-08Added to CISA Known Exploited Vulnerabilities catalog
2026-10-11CISA BOD 26-04 remediation deadline