CVE-2026-3415 Details
Description
The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges. Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.
A vulnerability exists in multiple WSO2 products, including API Manager, API Control Plane, Traffic Manager, and Universal Gateway, all versions 4.5.0 and 4.6.0, as well as API Manager versions 4.4.0, 4.3.0, 4.2.0, 4.1.0, 3.2.1, and 3.2.0. The issue arises within the XMLSchemaValidator Mediator, where the XML parser can be manipulated to resolve external entities in user-supplied XML during validation. This exploitation requires a high level of privilege to inject crafted XML payloads. Successful attacks may enable the reading of files from the server hosting the affected product, trigger unintended outbound requests, and cause excessive resource consumption, disrupting the product's availability.
Community users should apply the public fix available on the WSO2 GitHub repository. Support subscription holders can update to the specified update levels for their product version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5001/ | WSO2 LLC | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-776 | Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| WSO2 API Control Plane | 4.6.0 (semver) 4.5.0 (semver) |
CPE
Remediation
| |
| WSO2 API Manager | 4.6.0 (semver) 4.5.0 (semver) 4.4.0 (semver) 4.3.0 (semver) 4.2.0 (semver) 4.1.0 (semver) 3.2.1 (semver) 3.2.0 (semver) |
CPE
Remediation
| |
| WSO2 Traffic Manager | 4.6.0 (semver) 4.5.0 (semver) |
CPE
Remediation
| |
| WSO2 Universal Gateway | 4.6.0 (semver) 4.5.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | WSO2 LLC |
Volerion