Vulnerability in Apache Sling Security Bundle Affects Users
CVE-2026-94251

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-94251?

A security vulnerability in the Apache Sling Security Bundle's ContentDispositionFilter has been identified, where it only mediates a single address/API shape of a resource. This limitation may expose the system to unintended resource access vulnerabilities. Users are advised to upgrade to version 1.3.12 or later to mitigate this issue and enhance their security posture.

Affected Version(s)

Apache Sling Security Bundle 0 < 1.3.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Code
.