CVE-2026-73632CWE-567

CVE-2026-73632

Medium · published August 15, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
17.8
In the wild
Unconfirmed
What it is

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected.

This issue affects Apache Struts: 7.2.1.

Users are recommended to upgrade to version 7.3.0, which fixes the issue.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00262 · 17.8th percentile
Weakness
CWE-567 · Unsynchronized Access to Shared Data in a Multithreaded Context
Published
2026-08-15T15:16Z
Affected products (1)
ProductVersionsFixed in
apache/strutsall versions
References (1)
EPSS history
Timeline
  • 15 AUG 10:38Z
    Apache Struts: Shared serialization state in the JSON plugin
    cvelistv5