CVE-2026-73632: Apache Struts
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.
Affected products
- Apache Struts: version 7.2.1 only
Published 2026-08-15. Last modified 2026-08-18.