Cross-Site Scripting Vulnerability in Apache Sling XSS
CVE-2026-91999

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-91999?

A cross-site scripting vulnerability exists in Apache Sling XSS prior to version 2.4.12. This issue arises due to improper neutralization of user input during web page generation, allowing attackers to inject malicious scripts into web pages viewed by end users. Exploitation of this vulnerability could result in unauthorized access to sensitive information or session hijacking. Users are strongly advised to update to version 2.4.12 to remediate this security flaw.

Affected Version(s)

Apache Sling XSS 0 < 2.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Code
.