PatchSiren

WSO2 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL WSO2 CVE published 2026-08-06

CVE-2026-3418

The System REST API vulnerability (CVE-2026-3418) allows an authenticated publisher to upload files to arbitrary server-accessible locations due to insufficient validation on file type or destination. This issue, with a CVSS score of 9.1, requires authenticated administrative access with publisher privileges for exploitation. Successful exploitation could lead to remote code execution. The CVE record was [truncated]

HIGH WSO2 CVE published 2026-08-06

CVE-2026-3415

The CVE-2026-3415 vulnerability affects the SchemaValidator Mediator's XML and schema validation functionalities. Under certain conditions, the XML parser allows external entity resolution when handling user-supplied XML content during validation. Successful exploitation may allow highly privileged actors to read files within the server hosting the affected product and trigger outbound requests to uninten [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2025-6508

The Swagger UI Try-out console within API Publisher documentation allows loading an external Swagger API definition URL, overriding existing API definitions. This could expose sensitive information or initiate unintended backend service requests. Organizations using API Publisher documentation with Swagger UI Try-out console should review and update configurations. Evidence is limited; further review of v [truncated]

CRITICAL WSO2 CVE published 2026-08-06

CVE-2025-14561

CVE-2025-14561 is a critical vulnerability in multi-tenant deployments of the affected product, allowing a privileged user to perform operations impacting other tenants through Publisher REST APIs. The vulnerability has a CVSS score of 9 and is classified as CRITICAL. Organizations should be aware of the potential risks associated with this vulnerability, particularly in multi-tenant environments. The CVE [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2025-12317

The WSO2 product vulnerability (CVE-2025-12317) relates to improper handling of user role changes and authentication token validation. When internal roles are removed from a user, the system fails to invalidate previously issued authentication tokens associated with that user. This could allow users to retain their previous access privileges even after their roles have been revoked. The vulnerability has [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2024-6541

The Class Mediator in certain WSO2 products fails to correctly validate or sanitize `messageContext` properties, potentially allowing authenticated users to access or modify isolated system data. The impact depends on how `messageContext` properties are used within affected products. This vulnerability can lead to the disclosure of sensitive information belonging to other users or the unintended modificat [truncated]

CRITICAL WSO2 CVE published 2026-08-06

CVE-2026-1728

CVE-2026-1728 is a critical vulnerability in WSO2 products where tokens issued to low-privileged users are not sufficiently restricted. This allows low-privileged users to access product-level Admin REST APIs, potentially leading to full administrative account takeover. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Organizations should verify their inventory and check for low-pr [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2026-0637

CVE-2026-0637 involves a logging vulnerability in Wso2 products. When Event Publisher output adapters are configured with irrelevant properties, sensitive information may be logged without validation or sanitization. This issue could allow a malicious actor with access to 'wso2carbon' log files to retrieve sensitive data, such as user credentials, potentially leading to unauthorized access. Organizations [truncated]

LOW WSO2 CVE published 2026-08-06

CVE-2025-14779

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:28.980Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type, potentially leading to unintended deletion of secrets across the entire deployment. This [truncated]

LOW WSO2 CVE published 2026-08-06

CVE-2025-13736

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:28.657Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects systems using Multi-Attribute Login, allowing attackers to discover valid usernames, which can increase the risk of brute force attacks, social engineering attacks, and t [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2025-13394

The Ajax processor within the Carbon console is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to its use of HTTP GET for state-changing operations. This vulnerability allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions, potentially leading to data modification or account changes. The CVE record was published on 2026-08-06T08:16:28.210Z an [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2025-11850

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:27.923Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This CVE-2025-11850 vulnerability affects an unspecified product from Unknown Vendor, potentially leading to identity confusion and access restriction when secondary user stores are configured with [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2024-8995

The CVE record for CVE-2024-8995 was published on 2026-08-06T08:16:27.687Z and is currently classified as Undergoing Analysis by the NVD. The vulnerability involves the reuse of unused authorization codes issued to deleted users, potentially allowing unauthorized access to sensitive resources if an attacker possesses both the code and client credentials. This issue arises from improper invalidation or rem [truncated]

MEDIUM WSO2 CVE published 2026-08-06

CVE-2024-6832

The CVE record describes a vulnerability where the account locking mechanism fails when secondary user stores are inaccessible, allowing repeated authentication attempts with invalid credentials. Users in accessible stores are vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations without triggering account lockout.

MEDIUM WSO2 CVE published 2026-08-06

CVE-2024-10302

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input, allowing arbitrary unvalidated data to be included within user claims. This weakness can lead to various security risks, including content manipulation, redirection, user interface inconsistencies, unauthorized actions, and data exposure. Organizations using WSO2 products should review their configuration [truncated]

MEDIUM WSO2 CVE published 2026-07-20

CVE-2026-2445

The CVE record indicates that the affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of th [truncated]

HIGH WSO2 CVE published 2026-07-06

CVE-2026-4249

CVE-2026-4249 is a high-severity vulnerability in WSO2 API Manager and other products. The vulnerability allows unauthenticated remote attackers to inject malicious JSON data, leading to a persistent denial of service condition. Successful exploitation can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. Affected product deploymen [truncated]

MEDIUM WSO2 CVE published 2026-07-06

CVE-2025-8591

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve informatio [truncated]

MEDIUM WSO2 CVE published 2026-07-04

CVE-2024-1248

CVE-2024-1248 is a medium-severity vulnerability (CVSS Score: 4.8) affecting the silent Just-In-Time (JIT) provisioning feature in federated authentication implementations. The vulnerability allows an attacker to overwrite existing roles of local users with roles assigned to a federated user when a federated user shares a username with a local user. This issue requires a federated identity provider (IDP) [truncated]

LOW WSO2 CVE published 2026-07-04

CVE-2025-13475

CVE-2025-13475 is a vulnerability in the application consent management mechanism that fails to isolate consent scopes between tenants. This leads to unintended cross-tenant consent sharing, potentially exposing user data across tenants. The vulnerability has a CVSS score of 3.5 and is considered low severity. It has no impact if the deployment does not support multi-tenancy. The CVE was published on July 4, 2026.

Known exploited WSO2 CVE published 2022-04-25

CVE-2022-29464

CVE-2022-29464 is a WSO2 multiple-products vulnerability described as an unrestrictive file upload issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-25 and marked it as having known ransomware campaign use, which makes this a high-priority remediation item for any organization running affected WSO2 software.

MEDIUM Wso2 CVE published 2017-02-17

CVE-2016-4327

CVE-2016-4327 is a cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java 6.6 build SSJ-6.6-20090827-1616 and earlier. The issue allows a remote attacker to inject arbitrary web script or HTML through the PATH_INFO component, which can lead to script execution in a victim's browser under the affected site’s origin. NVD rates the issue as medium severity, with network attack vector [truncated]

MEDIUM Wso2 CVE published 2017-02-17

CVE-2016-4316

CVE-2016-4316 is a medium-severity cross-site scripting issue in WSO2 Carbon 4.4.5 affecting multiple administration-facing JSP endpoints. Because the issue is network-reachable and can influence what a user’s browser renders, organizations running this version should treat it as a real risk to administrative sessions and prioritize remediation planning.

MEDIUM Wso2 CVE published 2017-02-17

CVE-2016-4315

CVE-2016-4315 is a cross-site request forgery issue in WSO2 Carbon 4.4.5 that can be abused to make a privileged user’s browser send a shutdown request to the server-admin/proxy_ajaxprocessor.jsp endpoint. The practical impact is denial of service: if a privileged session is tricked into issuing the action, the server can be shut down without the attacker needing direct authentication to the target.

MEDIUM Wso2 CVE published 2017-02-17

CVE-2016-4314

CVE-2016-4314 is a directory traversal vulnerability in the LogViewer Admin Service of WSO2 Carbon 4.4.5. According to the NVD description, a remote authenticated administrator can supply dot-dot sequences in the logFile parameter to downloadgz-ajaxprocessor.jsp and read arbitrary files. NVD assigns CWE-22 and a CVSS 3.0 score of 4.9 (MEDIUM).

HIGH Wso2 CVE published 2017-02-17

CVE-2016-4312

CVE-2016-4312 affects WSO2 Identity Server 5.1.0 and is a high-impact XML external entity (XXE) issue in the XACML flow feature. A crafted XACML request sent to entitlement/eval-policy-submit.jsp can trigger unsafe XML processing, which may allow an authenticated attacker with access to XACML features to read local files, cause denial of service, or perform server-side request forgery (SSRF). The vulnerab [truncated]

HIGH Wso2 CVE published 2017-02-17

CVE-2016-4311

CVE-2016-4311 is a high-severity cross-site request forgery (CSRF) issue in the XACML flow feature of WSO2 Identity Server 5.1.0. A remote attacker could abuse a logged-in privileged user’s session to submit unintended XACML-related requests through entitlement/eval-policy-submit.jsp. The NVD record rates the issue as CVSS 3.0 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and maps it to CWE-352.