CVE-2026-4103 Details
Description
Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API documents are viewed. Successful exploitation may result in the execution of malicious scripts within the user's browser context when viewing API documentation. Users with permissions to access the API documentation through these portals may be impacted, potentially allowing attackers to perform actions on behalf of the user, depending on their session privileges.
A stored cross-site scripting vulnerability has been identified in the WSO2 Publisher Portal and Developer Portal. This issue arises from inadequate HTML sanitization, which allows untrusted user input to be rendered without proper encoding or neutralization. As a result, malicious JavaScript can be injected and executed when affected API documents are viewed. Users with permissions to access API documentation through these portals may be impacted, potentially enabling attackers to perform actions on behalf of the user, depending on their session privileges.
Users of WSO2 API Manager versions 4.2.0, 4.3.0, 4.4.0, 4.5.0, and 4.6.0 should add the 'sanitizeHtmlDocs' configuration to the 'settings.json' files in the Publisher Portal and Developer Portal. For WSO2 API Manager versions 3.2.0, 3.2.1, and 4.1.0, the 'sanitizeHtmlDocs' configuration should be added to the 'settings.js' files in the appropriate Jaggery app directories. WSO2 API Control Plane users should update to version 4.6.0 or 4.5.0, depending on their current version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-4844/ | WSO2 LLC | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| WSO2 API Control Plane | 4.6.0 (semver) 4.5.0 (semver) |
CPE
Remediation
| |
| WSO2 API Manager | 4.6.0 (semver) 4.5.0 (semver) 4.4.0 (semver) 4.3.0 (semver) 4.2.0 (semver) 4.1.0 (semver) 3.2.1 (semver) 3.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | WSO2 LLC |
Volerion