Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-50164

74
FAUCET Score

CVE-2023-50164 is a critical path traversal vulnerability in Apache Struts that allows attackers to upload malicious files, potentially leading to Remote Code Execution. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. This vulnerability is being actively exploited in the wild, as evidenced by multiple media reports and a high EPSS score, despite the lack of public exploit code in common repositories like Metasploit or ExploitDB. Users are urged to upgrade to Struts 2.5.33 or 6.3.0.2 or greater immediately.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, <= 2.5.32CPE match
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
>= 6.0.0, <= 6.3.0.1CPE match
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
>= 2.0.0, < 2.5.33CPE matchmatch criteria
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.3.0.2CPE matchmatch criteria
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
80.82%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.8082 is in the 98th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

mavenpatch availablevia ghsa
Product: org.apache.struts:struts2-coreFixed in: 6.3.0.2
mavenpatch availablevia ghsa
Product: org.apache.struts:struts2-coreFixed in: 2.5.33
barracudavendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
clamavvendor investigatingvia llm_extracted
consulvendor investigatingvia llm_extracted
freshrssvendor investigatingvia llm_extracted
qdrantvendor investigatingvia llm_extracted
symantecvendor investigatingvia llm_extracted
verbbvendor investigatingvia llm_extracted

Vendor Advisories (10)

qdrantllm-qdrant-bef6ffbb72535062

Apache Struts 2 Vulnerability

Jan 22, 2024
boschllm-bosch-ec1f0ac6fe16414b

Apache Struts 2 Vulnerability

Jan 22, 2024
freshrssllm-freshrss-435f2a15a143b1bd

Apache Struts 2 Vulnerability

Jan 22, 2024
barracudallm-barracuda-fb8da9c020da837b

Apache Struts 2 Vulnerability

Jan 22, 2024
symantecllm-symantec-5c871f92bac8c877

Apache Struts 2 Vulnerability

Jan 22, 2024
verbbllm-verbb-00c60ad6a26d16fc

Apache Struts 2 Vulnerability

Jan 22, 2024
consulllm-consul-c0cbd0cef171d5c6

Apache Struts 2 Vulnerability

Jan 22, 2024
clamavllm-clamav-a46c669740e1b64f

Apache Struts 2 Vulnerability

Jan 22, 2024
mavenGHSA-2j39-qcjm-428wcritical

Apache Struts vulnerable to path traversal

Dec 7, 2023
redhatCVE-2023-50164Critical

Struts: File upload component had a directory traversal vulnerability

Dec 7, 2023

References

packetstormsecurity.com / files/176157/Struts-S2-066-File-Upload-Remote-Code-Execution.html
Third Party AdvisoryVDB Entry
lists.apache.org / thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhj
Mailing ListPatch
security.netapp.com / advisory/ntap-20231214-0010
Third Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2023/12/07/1
Mailing List