Junglewise Threat Intelligence

CVE-2026-91999: Apache Sling XSS cross-site scripting in web console plugin

CVE-2026-91999 · Severity: medium · CVSS 6.1 · Published 2026-09-23

Technologies: Apache Sling XSS. Vendors: Apache.

Executive brief

Apache Sling XSS is a library used to prevent cross-site scripting attacks in web applications. A cross-site scripting vulnerability in the web console plugin allows attackers to inject malicious scripts that execute in users' browsers, potentially stealing session tokens, credentials, or sensitive data. Users should upgrade to version 2.4.12 to resolve the issue.

Technical details

An improper input neutralization vulnerability in the Apache Sling XSS web console plugin allows reflected or stored cross-site scripting (XSS) attacks. The vulnerability stems from inadequate escaping of user-supplied input during HTML generation. An attacker can craft malicious input that bypasses XSS protections, executing arbitrary JavaScript in the context of a victim's browser session.

Affected products

  • Apache Sling XSS before 2.4.12

Timeline

  • 2026-09-23: disclosed

References

Related threats