CVE-2026-3096 Details
Description
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.
A vulnerability exists in WSO2 API Control Plane versions 4.6.0 and 4.5.0, as well as WSO2 API Manager versions 4.6.0, 4.5.0, 4.4.0, 4.3.0, 4.2.0, 4.1.0, 3.2.1, and 3.2.0. The issue arises because the web portals can open external links in a new tab, while the original window can still interact with the new page. This could enable an attacker to manipulate the trusted application window after a user clicks a malicious link, potentially leading to phishing attacks, credential theft, or other unauthorized actions on the trusted site.
Users can apply the public fix available on the WSO2 GitHub repository. For those with a WSO2 support subscription, the update can be applied through the WSO2 Updates service.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5164/ | WSO2 LLC | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | WSO2 LLC |
| CWE-603 | Use of Client-Side Authentication | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| WSO2 API Control Plane | 4.6.0 (semver) 4.5.0 (semver) |
CPE
Remediation
| |
| WSO2 API Manager | 4.6.0 (semver) 4.5.0 (semver) 4.4.0 (semver) 4.3.0 (semver) 4.2.0 (semver) 4.1.0 (semver) 3.2.1 (semver) 3.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | New CVE Received | WSO2 LLC |
Volerion