Cross-Site Scripting Vulnerability in Apache Sling by Apache
CVE-2026-91852

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-91852?

An improper neutralization of user input during the web page generation process in Apache Sling's XSS library allows attackers to execute arbitrary JavaScript code in the context of a user's session. This may lead to data theft, session hijacking, or defacement of the site. Users running versions prior to 2.4.12 are strongly encouraged to upgrade to the latest version to mitigate potential security risks.

Affected Version(s)

Apache Sling XSS 0 < 2.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Sling would like to thank the github user n0mi1k, the group of Mohsen Iranmanesh, Sina Moradi Sabet, Sina Marefat, Ali Javidi Ghasr and Mohammad A. Tayebi and The Apache Software Foundation for reporting this issue
.