CVE-2026-94243: Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence
Low-severity flaw in Apache Sling Security Bundle's RefererFilter accepting weak evidence, patched in version 1.3.2.
A low-severity vulnerability, CVE-2026-94243, has been disclosed in the Apache Sling Security Bundle. The RefererFilter accepts weaker-than-origin evidence, which could lead to security bypass. Users are advised to update to version 1.3.2 to remediate the issue.
- Low-severity vulnerability in Apache Sling Security Bundle.
- RefererFilter accepts weaker-than-origin evidence.
- Patched in version 1.3.2.
Vulnerabilities mentionedAll →
- CVE-2026-942437.3—CSRF Protection Bypass in Apache Sling Security Bundle ReferrerFilterpublished · Apache Software Foundation Apache Sling Security Bundle
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-94243 | CSRF Protection Bypass in Apache Sling Security Bundle ReferrerFilter Apache Sling Security Bundle before version 1.3.2 contains an origin validation error (CWE-346) in its ReferrerFilter, the component that guards against cross-site request forgery by checking the Referer/Origin header on state-changing requests. The filter accepts 'weaker-than-origin' evidence, meaning a request whose referrer does not strictly match the target origin can still pass the CSRF check. An attacker who lures an authenticated user of a Sling-based application (Sling underpins Adobe Experience Manager) to a malicious web page could silently submit forged POST requests that pass the filter and perform actions as the victim, such as modifying or publishing content, changing configurations, or creating users. Any deployment running the Sling Security Bundle older than 1.3.2 is affected; exploitation status is currently unknown, with no public proof of concept and no listing in the CISA Known Exploited Vulnerabilities catalog. The issue is fixed in version 1.3.2. |
Posted by Joerg Hoh on Sep 23 Severity: low Affected versions: - Apache Sling Security Bundle before 1.3.2 Description: A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue. This issue is being tracked as SLING-13312 Credit: The Apache Software Foundation (finder) Claude Code...
This source does not provide full text. Read it at seclists.org.