CVE-2016-3090: Apache Struts

High severity, CVSS 8.8. EPSS: 5.7% chance of exploitation in the next 30 days.

The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.

Affected products

  • Apache Struts: version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; version 2.0.6 only; …

Published 2017-10-30. Last modified 2026-06-17.