SEPTEMBER 30, 2026
Live Feed
Back to database
Case File

CVE-2026-73192

MEDIUM · CVSS 6.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-09-30

CyberRota Analysis

AI-Generated

Apache Sling XSS versions 2.4.10 and earlier are vulnerable to reflected cross-site scripting (XSS) due to improper input neutralization in the XSSAPI.getValidHref() method. This flaw allows attackers to inject malicious scripts if they can submit unsanitized values, potentially compromising user sessions or stealing sensitive information. Organizations using affected versions should prioritize upgrading to Apache Sling XSS version 2.4.12 or later to mitigate this risk.

CVE
CVE-2026-73192
Severity
MEDIUM
CVSS
6.1
EPSS
0.17%
Apache

Original NVD Description

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an application, the attacker needs to be able to submit a value which is not correctly sanitized by that library. Upgrade to Apache Sling XSS >= 2.4.12

Related CVEs

Other vulnerabilities affecting the same vendor(s)