Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-3415 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges. Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')WSO2 LLC

Affected Products

ProductVersions
WSO2 API Control Plane
4.6.0 (semver)
4.5.0 (semver)

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: 17moderate effort
  • Upgrade: 54moderate effort
  • Workaround:moderate effort

    Migrate to the latest unaffected version of WSO2 API Control Plane.

WSO2 API Manager
4.6.0 (semver)
4.5.0 (semver)
4.4.0 (semver)
4.3.0 (semver)
4.2.0 (semver)

CPE

  • cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 16moderate effort
  • Upgrade: 53moderate effort
  • Upgrade: 68moderate effort
  • Upgrade: 105moderate effort
  • Upgrade: 194moderate effort
  • Upgrade: 254moderate effort
  • Upgrade: 91moderate effort
  • Upgrade: 472moderate effort
  • Workaround:moderate effort

    Migrate to the latest unaffected version of WSO2 API Manager.

WSO2 Traffic Manager
4.6.0 (semver)
4.5.0 (semver)

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: 16moderate effort
  • Upgrade: 52moderate effort
  • Workaround:moderate effort

    Migrate to the latest unaffected version of WSO2 Traffic Manager.

WSO2 Universal Gateway
4.6.0 (semver)
4.5.0 (semver)

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: 16moderate effort
  • Upgrade: 53moderate effort
  • Workaround:moderate effort

    Migrate to the latest unaffected version of WSO2 Universal Gateway.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-3415
NVD Published Date:
Aug 6, 2026
NVD Last Modified:
Aug 31, 2026
Source:
WSO2 LLC
CVE-2026-3415 Details - Not Deferred