CVE-2026-91999: Apache Sling XSS: Improper escaping in the XSS Webconsole plugin
Apache Sling XSS before 2.4.12 contains a low-severity cross-site scripting flaw, CVE-2026-91999.
Apache disclosed CVE-2026-91999, a cross-site scripting flaw from improper input neutralization in the Apache Sling XSS Webconsole plugin. Versions before 2.4.12 are affected, and users are advised to upgrade to 2.4.12. Apache rates the issue low and tracks it as SLING-13335. The advisory does not say the flaw is being exploited.
- Improper escaping in the XSS Webconsole plugin allows cross-site scripting.
- Apache Sling XSS before 2.4.12 is affected; 2.4.12 fixes it.
- Apache rates severity low and tracks the bug as SLING-13335.
- The advisory does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-919996.1—Cross-Site Scripting in Apache Sling XSS Webconsole Plugin (pre-2.4.12)published · Apache Software Foundation Apache Sling XSS
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91999 | Cross-Site Scripting in Apache Sling XSS Webconsole Plugin (pre-2.4.12) Apache Sling XSS before 2.4.12 contains a cross-site scripting flaw (CWE-79) caused by improper neutralization of input during web page generation, reported as improper escaping in the XSS Webconsole plugin. An attacker crafts a request whose payload is reflected unescaped into the plugin's generated web console page, and the malicious script executes when a victim is tricked into viewing that page (user interaction required, no privileges needed). Successful exploitation lets the attacker run script in the victim's browser in the context of the Sling console, yielding limited confidentiality and integrity impact such as session or token theft and actions performed as the victim, with no availability impact. Any deployment using Apache Sling XSS versions before 2.4.12 is affected; users are advised to upgrade to 2.4.12. There is no known public proof of concept, the issue is not in CISA's KEV catalog, and no exploitation has been observed. |
Posted by Joerg Hoh on Sep 23 Severity: low Affected versions: - Apache Sling XSS before 2.4.12 Description: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. This issue is being tracked as SLING-13335 Credit: The Apache Software Foundation (finder) Claude Code...
This source does not provide full text. Read it at seclists.org.