OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94243

HIGH · CVSS 7.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Apache Sling Security Bundle is vulnerable due to the ReferrerFilter accepting weaker-than-origin evidence, potentially allowing unauthorized access to resources. This could lead to security breaches for applications relying on this component. Organizations using affected versions prior to 1.3.2 should prioritize upgrading to mitigate the risk.

CVE
CVE-2026-94243
Severity
HIGH
CVSS
7.3
EPSS
0.24%
Apache

Original NVD Description

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)