Review reviewCritical

CVE-2026-2053

WSO2 WSO2 API Manager, api manager

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from e...

CVSS
10
EPSS
0.24%
14.8% percentile
CISA KEV
Not listed
Published
2026.06.26
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.24%
Technical severityCVSS 10

Vulnerability overview

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from e...

Affected product and versions

Product
WSO2 WSO2 API Manager, api manager
Affected versions
3.1.0, 3.2.0, 3.2.1, 4.0.0, 4.2.0, >= 3.1.0 < 3.1.0.360, >= 3.2.0 < 3.2.0.465, >= 3.2.1 < 3.2.1.84, >= 4.0.0 < 4.0.0.385, >= 4.2.0 < 4.2.0.189
Fixed versions
3.1.0.360, 3.2.0.465, 3.2.1.84, 4.0.0.385, 4.2.0.189

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that WSO2 WSO2 API Manager, api manager and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-918