Description
A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence.



This issue affects Apache Sling Security Bundle: before 1.3.2.



Users are recommended to upgrade to version 1.3.2, which fixes the issue.
Published: 2026-09-23
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Referrer Validation Bypass
Action: Apply Patch
AI Analysis

Impact

The Apache Sling Security Bundle ReferrerFilter accepts referrer evidence that is weaker than the originating server, allowing an attacker to forge or modify the Referer header and undermine the framework’s security controls that rely on strict origin validation. This flaw can be exploited to bypass access restrictions that depend on the Referer header, potentially granting unauthorized access to protected resources.

Affected Systems

All installations of the Apache Sling Security Bundle that are running a version earlier than 1.3.2 are affected, regardless of deployment environment. The vulnerability is present in any release before the fix included in bundle version 1.3.2.

Risk and Exploitability

The EPSS score is under 1%, indicating a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to send HTTP requests with a forged Referer header, typically over an open network connection. While the CVSS metric is not supplied, the CWE-346 weakness and the reliance on forged headers suggest that a skilled attacker could gain unauthorized access if Referer validation is trusted for authorization.

Generated by OpenCVE AI on September 23, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Apache Sling Security Bundle to version 1.3.2 or later.
  • If upgrading is delayed, enforce HTTPS-only traffic and configure the bundle to validate the Referer header against a strict whitelist of allowed origins.
  • Configure the bundle to reject any requests lacking a valid Referer header, ensuring that all protected resources require a strong origin before processing.

Generated by OpenCVE AI on September 23, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.
Title Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence
Weaknesses CWE-346
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-23T15:16:37.469Z

Reserved: 2026-09-21T08:18:46.397Z

Link: CVE-2026-94243

cve-icon Vulnrichment

Updated: 2026-09-23T15:16:17.610Z

cve-icon NVD

Status : Received

Published: 2026-09-23T10:17:08.440

Modified: 2026-09-23T16:16:48.567

Link: CVE-2026-94243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:15:05Z

Weaknesses