Apache Sling Security Bundle Vulnerability in ReferrerFilter
CVE-2026-94243

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-94243?

A vulnerability exists in the Apache Sling Security Bundle that allows for the acceptance of weaker-than-origin evidence by the ReferrerFilter. This could potentially lead to unauthorized access or manipulation of data by malicious entities. Users are encouraged to promptly update to version 1.3.2, which rectifies this security flaw and fortifies the overall security posture of the application.

Affected Version(s)

Apache Sling Security Bundle 0 < 1.3.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Code
.