Junglewise Threat Intelligence

CVE-2026-91928: Apache Sling XSS cross-site scripting vulnerability

CVE-2026-91928 · Severity: medium · CVSS 6.1 · Published 2026-09-23

Technologies: Apache Sling XSS. Vendors: Apache.

Executive brief

Apache Sling XSS is a web application library that protects against malicious scripts in user-generated content. A cross-site scripting (XSS) vulnerability in versions before 2.4.12 allows attackers to bypass sanitization protections and inject malicious scripts into web pages, potentially leading to session hijacking, credential theft, or malware distribution to users viewing affected pages.

Technical details

This is an improper input neutralization vulnerability in Apache Sling XSS that allows bypass of XSS protections through unsanitized user input during web page generation. The vulnerability affects versions before 2.4.12 and can be exploited via network access with no authentication required if the affected application processes untrusted input. Exploitation allows an attacker to execute arbitrary JavaScript in the context of affected users' browsers; the issue is resolved in version 2.4.12.

Affected products

  • Apache Sling XSS before 2.4.12

Timeline

  • 2026-09-23: disclosed

References

Related threats