CVE-2026-91928: Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms
Apache Sling XSS before 2.4.12 has a moderate XSS sanitizer bypass, CVE-2026-91928.
Apache Sling XSS before 2.4.12 fails to neutralize input during web page generation, enabling cross-site scripting. The moderate-severity issue also involves sanitizer bypass, uncontrolled resource consumption, and failure of protection mechanisms. Users are advised to upgrade to 2.4.12. It is tracked as SLING-13333 and CVE-2026-91928, with no exploitation reported.
- Affects Apache Sling XSS before 2.4.12
- Rated moderate; fixed in version 2.4.12
- Tracked as CVE-2026-91928 and SLING-13333
- Covers sanitizer bypass and uncontrolled resource use
Vulnerabilities mentionedAll →
- CVE-2026-919286.1—XSS Sanitizer Bypass in Apache Sling XSS Library (< 2.4.12)published · Apache Software Foundation Apache Sling XSS (org.apache.sling.xss)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91928 | XSS Sanitizer Bypass in Apache Sling XSS Library (< 2.4.12) Apache Sling XSS, the Java library (org.apache.sling.xss) that Sling-based applications use to sanitize user-supplied HTML and rich text before rendering, fails to properly neutralize crafted input, allowing a cross-site scripting (XSS) protection bypass. An attacker submits specially structured markup that slips past the sanitizer; when a victim views a page containing that content, the attacker's script executes in the victim's browser session, enabling session/cookie theft, defacement, or in-session actions against Sling-based applications such as Adobe Experience Manager, which embeds this library. The flaw (CVSS 3.1: 6.1, medium) is network-reachable without privileges but requires user interaction and yields only limited confidentiality and integrity impact. All deployments using Apache Sling XSS before version 2.4.12 are affected, and the fix is an upgrade to 2.4.12. No public proof-of-concept is known, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and there is no indication of in-the-wild exploitation. |
Posted by Joerg Hoh on Sep 23 Severity: moderate Affected versions: - Apache Sling XSS before 2.4.12 Description: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. This issue is being tracked as SLING-13333 Credit: The Apache Software Foundation (finder) Claude...
This source does not provide full text. Read it at seclists.org.