CVE-2026-94243: Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence
Published Sep 23, 2026
·Updated
A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence.
This issue affects Apache Sling Security Bundle: before 1.3.2.
Users are recommended to upgrade to version 1.3.2, which fixes the issue.
Affected Software
1 affected component
Apache Sling Security Bundle<1.3.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Sling Security Bundleto a version that resolves this vulnerability.Fixed in 1.3.2
Event History
Sep 23, 2026
CVE Published
via MITRE·09:43 AM
Data Sourced
via MITRE·09:43 AM
DescriptionWeakness
Data Sourced
via NVD·10:17 AM
DescriptionWeakness
Frequently Asked Questions
1
Which versions need to be remediated?
Apache Sling Security Bundle versions before 1.3.2 are affected. Upgrade to version 1.3.2, which fixes the issue.