PatchSiren

WSO2 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WSO2 CVE published 2026-09-15

CVE-2026-19515

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary operating system commands through the unit test execution flow. Successful exploitation could lead to arbitrary OS command execution on the system where the VS Code extensio [truncated]

MEDIUM WSO2 CVE published 2026-09-15

CVE-2025-5802

CVE-2025-5802 allows attackers to discover valid usernames through the self-registration flow, which can facilitate subsequent attacks like brute force and phishing. Defenders should assess exposure, prioritize verification of affected versions and remediation, and consider compensating controls. The vulnerability affects user registration and authentication systems, allowing attackers to use valid userna [truncated]

LOW WSO2 CVE published 2026-09-15

CVE-2025-13166

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically ti [truncated]

MEDIUM WSO2 CVE published 2026-09-14

CVE-2026-4103

CVE-2026-4103 debrief based on CVE Program and NVD records. The vulnerability involves insufficient HTML sanitization in Publisher Portal and Developer Portal, allowing untrusted user input to be rendered without proper encoding or neutralization. This enables JavaScript injection and execution when affected API documents are viewed. Successful exploitation may result in malicious script execution within [truncated]

MEDIUM WSO2 CVE published 2026-09-10

CVE-2026-3096

CVE-2026-3096 allows attackers to manipulate trusted application windows after users click malicious external links, potentially leading to phishing or unauthorized actions within the trusted site context. The vulnerability arises from the product's web portals allowing external links to be opened in a new browser tab, retaining access to the originating window. This access can be exploited to interact wi [truncated]

MEDIUM WSO2 CVE published 2026-09-03

CVE-2026-3416

A vulnerability in WSO2 API Manager's API Publisher component allows attackers to predict shared secrets for Webhook HMAC validation, enabling them to forge event payloads with valid HMAC signatures and bypass API Gateway authenticity checks. This issue arises from the use of a non-cryptographic pseudorandom number generator (PRNG) that lacks sufficient entropy for security-sensitive operations. Successfu [truncated]

CRITICAL WSO2 CVE published 2026-08-06

CVE-2026-3418

The System REST API vulnerability (CVE-2026-3418) allows an authenticated publisher to upload files to arbitrary server-accessible locations due to insufficient validation on file type or destination. This issue, with a CVSS score of 9.1, requires authenticated administrative access with publisher privileges for exploitation. Successful exploitation could lead to remote code execution. The CVE record was [truncated]

HIGH WSO2 CVE published 2026-08-06

CVE-2026-3415

The CVE-2026-3415 vulnerability affects the SchemaValidator Mediator's XML and schema validation functionalities. Under certain conditions, the XML parser allows external entity resolution when handling user-supplied XML content during validation. Successful exploitation may allow highly privileged actors to read files within the server hosting the affected product and trigger outbound requests to uninten [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2025-6508

The Swagger UI Try-out console within API Publisher documentation allows loading an external Swagger API definition URL, overriding existing API definitions. This could expose sensitive information or initiate unintended backend service requests. Organizations using API Publisher documentation with Swagger UI Try-out console should review and update configurations. Evidence is limited; further review of v [truncated]

CRITICAL WSO2 CVE published 2026-08-06

CVE-2025-14561

CVE-2025-14561 is a critical vulnerability in multi-tenant deployments of the affected product, allowing a privileged user to perform operations impacting other tenants through Publisher REST APIs. The vulnerability has a CVSS score of 9 and is classified as CRITICAL. Organizations should be aware of the potential risks associated with this vulnerability, particularly in multi-tenant environments. The CVE [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2025-12317

The WSO2 product vulnerability (CVE-2025-12317) relates to improper handling of user role changes and authentication token validation. When internal roles are removed from a user, the system fails to invalidate previously issued authentication tokens associated with that user. This could allow users to retain their previous access privileges even after their roles have been revoked. The vulnerability has [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2024-6541

The Class Mediator in certain WSO2 products fails to correctly validate or sanitize `messageContext` properties, potentially allowing authenticated users to access or modify isolated system data. The impact depends on how `messageContext` properties are used within affected products. This vulnerability can lead to the disclosure of sensitive information belonging to other users or the unintended modificat [truncated]

CRITICAL WSO2 CVE published 2026-08-06

CVE-2026-1728

CVE-2026-1728 is a critical vulnerability in WSO2 products where tokens issued to low-privileged users are not sufficiently restricted. This allows low-privileged users to access product-level Admin REST APIs, potentially leading to full administrative account takeover. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Organizations should verify their inventory and check for low-pr [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2026-0637

CVE-2026-0637 involves a logging vulnerability in Wso2 products. When Event Publisher output adapters are configured with irrelevant properties, sensitive information may be logged without validation or sanitization. This issue could allow a malicious actor with access to 'wso2carbon' log files to retrieve sensitive data, such as user credentials, potentially leading to unauthorized access. Organizations [truncated]

LOW WSO2 CVE published 2026-08-06

CVE-2025-14779

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:28.980Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type, potentially leading to unintended deletion of secrets across the entire deployment. This [truncated]

LOW WSO2 CVE published 2026-08-06

CVE-2025-13736

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:28.657Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects systems using Multi-Attribute Login, allowing attackers to discover valid usernames, which can increase the risk of brute force attacks, social engineering attacks, and t [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2025-13394

The Ajax processor within the Carbon console is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to its use of HTTP GET for state-changing operations. This vulnerability allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions, potentially leading to data modification or account changes. The CVE record was published on 2026-08-06T08:16:28.210Z an [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2025-11850

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:27.923Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This CVE-2025-11850 vulnerability affects an unspecified product from Unknown Vendor, potentially leading to identity confusion and access restriction when secondary user stores are configured with [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2024-8995

The CVE record for CVE-2024-8995 was published on 2026-08-06T08:16:27.687Z and is currently classified as Undergoing Analysis by the NVD. The vulnerability involves the reuse of unused authorization codes issued to deleted users, potentially allowing unauthorized access to sensitive resources if an attacker possesses both the code and client credentials. This issue arises from improper invalidation or rem [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2024-6832

The CVE record describes a vulnerability where the account locking mechanism fails when secondary user stores are inaccessible, allowing repeated authentication attempts with invalid credentials. Users in accessible stores are vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations without triggering account lockout.

MEDIUM WSO2 CVE published 2026-08-06

CVE-2024-10302

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input, allowing arbitrary unvalidated data to be included within user claims. This weakness can lead to various security risks, including content manipulation, redirection, user interface inconsistencies, unauthorized actions, and data exposure. Organizations using WSO2 products should review their configuration [truncated]

MEDIUM WSO2 CVE published 2026-07-20

CVE-2026-2445

The CVE record indicates that the affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of th [truncated]

HIGH WSO2 CVE published 2026-07-06

CVE-2026-4249

CVE-2026-4249 is a high-severity vulnerability in WSO2 API Manager and other products. The vulnerability allows unauthenticated remote attackers to inject malicious JSON data, leading to a persistent denial of service condition. Successful exploitation can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. Affected product deploymen [truncated]

MEDIUM WSO2 CVE published 2026-07-06

CVE-2025-8591

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve informatio [truncated]

MEDIUM WSO2 CVE published 2026-07-04

CVE-2024-1248

CVE-2024-1248 is a medium-severity vulnerability (CVSS Score: 4.8) affecting the silent Just-In-Time (JIT) provisioning feature in federated authentication implementations. The vulnerability allows an attacker to overwrite existing roles of local users with roles assigned to a federated user when a federated user shares a username with a local user. This issue requires a federated identity provider (IDP) [truncated]

LOW WSO2 CVE published 2026-07-04

CVE-2025-13475

CVE-2025-13475 is a vulnerability in the application consent management mechanism that fails to isolate consent scopes between tenants. This leads to unintended cross-tenant consent sharing, potentially exposing user data across tenants. The vulnerability has a CVSS score of 3.5 and is considered low severity. It has no impact if the deployment does not support multi-tenancy. The CVE was published on July 4, 2026.

HIGH WSO2 CVE published 2026-02-19

CVE-2025-12107

The Velocity template engine in WSO2 Identity Server is vulnerable to arbitrary template syntax injection due to insufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax, potentially leading to remote code execution, data manipulation, and unauthorized access to sensitive information. Organizations using WSO2 Identity [truncated]

Known exploited WSO2 CVE published 2022-04-25

CVE-2022-29464

CVE-2022-29464 is a WSO2 multiple-products vulnerability described as an unrestrictive file upload issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-25 and marked it as having known ransomware campaign use, which makes this a high-priority remediation item for any organization running affected WSO2 software.

MEDIUM Wso2 CVE published 2017-02-17

CVE-2016-4327

CVE-2016-4327 is a cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java 6.6 build SSJ-6.6-20090827-1616 and earlier. The issue allows a remote attacker to inject arbitrary web script or HTML through the PATH_INFO component, which can lead to script execution in a victim's browser under the affected site’s origin. NVD rates the issue as medium severity, with network attack vector [truncated]

MEDIUM Wso2 CVE published 2017-02-17

CVE-2016-4316

CVE-2016-4316 is a medium-severity cross-site scripting issue in WSO2 Carbon 4.4.5 affecting multiple administration-facing JSP endpoints. Because the issue is network-reachable and can influence what a user’s browser renders, organizations running this version should treat it as a real risk to administrative sessions and prioritize remediation planning.