← All Advisories

CVE-2026-94243

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-94243

Key Details

CVECVE-2026-94243
CVSS Score / Version7.3 (High) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is low; availability impact is low.
Affected productsApache Software Foundation Apache Sling Security Bundle
Classified asCWE-346 (Origin Validation Error)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apache Software FoundationApache Sling Security Bundle
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence.

This issue affects Apache Sling Security Bundle: before 1.3.2.

Users are recommended to upgrade to version 1.3.2, which fixes the issue. (NVD)

What to Do

Monitor Apache Software Foundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-94243
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-94243