Apache Struts CVE-2023-50164 Remote Code Execution Vulnerability

description-logoDescription

Path traversal via manipulated file-upload parameters allows remote code execution in Apache Struts versions before 2.5.33 or 6.3.0.2.

description-logoOutbreak Alert

FortiGuard Labs has detected on-going exploit attempts targeting a recently patched Apache Struts 2 vulnerability. Attackers can manipulate file upload parameters to enable path traversal, potentially leading to malicious file upload. This may result in Remote Code Execution, allowing attackers to run arbitrary code, steal data, or compromise entire systems.

View the full Outbreak Alert Report

affected-products-logoAffected Applications

Apache Struts

Version Updates

Date Version Status Detail
2026-02-21 2.00700
New
Apache Struts
2023-12-15 2.00333
New
Apache Struts