CVE-2026-94243

NONE
Updated Sep 23, 2026
Apache Software Foundation
Parameter Value
Affected Versions before 1.3.2.
Fixed In 1.3.2
Type CWE-346 (Origin Validation Error)
Vendor Apache Software Foundation
Public PoC No

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.

Vulnerable Products

apache software foundation:apache sling security bundle