CVE-2026-2053
WSO2 WSO2 API Manager, api manager
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from e...
- CVSS
- 10
- EPSS
- 0.24% 14.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.26