Junglewise Threat Intelligence

CVE-2026-91852: Apache Sling XSS cross-site scripting vulnerability

CVE-2026-91852 · Severity: medium · CVSS 6.1 · Published 2026-09-23

Technologies: Apache Sling XSS. Vendors: Apache.

Executive brief

Apache Sling XSS is a library component used to prevent cross-site scripting attacks in web applications. This vulnerability is itself a cross-site scripting flaw in the library's input handling, allowing attackers to inject malicious scripts into web pages. An organization relying on this library for XSS protection may unknowingly expose users to script injection attacks.

Technical details

The vulnerability is an improper neutralization of user input during web page generation (CWE-79), affecting Apache Sling XSS versions before 2.4.12. The flaw allows malicious input to bypass XSS protections and be rendered as script code in generated web pages. A fix is available in version 2.4.12 and later.

Affected products

  • Apache Sling XSS before 2.4.12

Timeline

  • 2026-09-23: disclosed

References

Related threats