CVE-2026-94243: Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence
Low-severity flaw in Apache Sling Security Bundle's RefererFilter accepting weak evidence, patched in version 1.3.2.
A low-severity vulnerability, CVE-2026-94243, has been disclosed in the Apache Sling Security Bundle. The RefererFilter accepts weaker-than-origin evidence, which could lead to security bypass. Users are advised to update to version 1.3.2 to remediate the issue.
15