CVE-2026-2053 Details
Description
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.
A server-side request forgery (SSRF) vulnerability has been identified in WSO2 API Manager versions 4.2.0, 4.0.0, 3.2.1, 3.2.0, and 3.1.0. The vulnerability arises in the message flow component when processing WS-Addressing headers, which are not adequately validated or restricted. This allows an unauthenticated attacker to manipulate the headers and control the destination of server-initiated requests. Exploitation could lead to unauthorized access to internal network resources or services typically not available from external networks.
Users of WSO2 API Manager can migrate to the latest unaffected version. For support subscription holders, it is recommended to update to the specified update level or a higher one. Instructions for applying the update are available through WSO2 Updates.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5072/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 api manager | >= 3.1.0, < 3.1.0.360 >= 3.2.0, < 3.2.0.465 >= 3.2.1, < 3.2.1.84 >= 4.0.0, < 4.0.0.385 >= 4.2.0, < 4.2.0.189 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 27, 2026 | Initial Analysis | [email protected] |
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | WSO2 LLC |