Cross-Site Scripting Vulnerability in Apache Sling by Apache
CVE-2026-91928

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-91928?

A cross-site scripting (XSS) vulnerability exists in Apache Sling XSS that improperly neutralizes user input during web page generation. This flaw could potentially allow an attacker to inject malicious scripts into web pages that may be viewed by other users, compromising user data and web application integrity. It is essential for users to upgrade to version 2.4.12 to protect against this vulnerability.

Affected Version(s)

Apache Sling XSS 0 < 2.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Code
.