Exposure of Data Element to Wrong Session in Apache Struts - CVE-2026-73632

 

Exposure of Data Element to Wrong Session in Apache Struts - CVE-2026-73632

Published: August 24, 2026


Vulnerability identifier: #VU144837
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-73632
CWE-ID: CWE-488
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to shared serialization state in the JSON plugin when handling concurrent SMD / JSON-RPC requests through the JSON interceptor. A remote attacker can send concurrent crafted requests to disclose sensitive information.

Only the SMD / JSON-RPC handling of the JSON interceptor is affected, and this functionality is not enabled by default. Applications using the json result type are not affected.


Affected software

Apache Struts

How to mitigate CVE-2026-73632

Install security update from vendor's website.

Apache Struts - update to 7.3.0

External References

Related Security Bulletins