4.4
CVE-2026-0637
- EPSS 0.11%
- Veröffentlicht 06.08.2026 08:16:29
- Zuletzt bearbeitet 12.08.2026 19:29:05
- CVE-Watchlists
- Unerledigt
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2 ≫ Api Control Plane Version >= 4.5.0 < 4.5.0.50
Wso2 ≫ Api Control Plane Version >= 4.6.0 < 4.6.0.14
Wso2 ≫ Api Manager Version >= 3.1.0 < 3.1.0.357
Wso2 ≫ Api Manager Version >= 3.2.0 < 3.2.0.465
Wso2 ≫ Api Manager Version >= 3.2.1 < 3.2.1.84
Wso2 ≫ Api Manager Version >= 4.1.0 < 4.1.0.249
Wso2 ≫ Api Manager Version >= 4.2.0 < 4.2.0.189
Wso2 ≫ Api Manager Version >= 4.3.0 < 4.3.0.100
Wso2 ≫ Api Manager Version >= 4.4.0 < 4.4.0.64
Wso2 ≫ Api Manager Version >= 4.5.0 < 4.5.0.49
Wso2 ≫ Api Manager Version >= 4.6.0 < 4.6.0.13
Wso2 ≫ Identity Server Version >= 5.10.0 < 5.10.0.386
Wso2 ≫ Identity Server Version >= 5.11.0 < 5.11.0.433
Wso2 ≫ Identity Server Version >= 6.0.0 < 6.0.0.260
Wso2 ≫ Identity Server Version >= 6.1.0 < 6.1.0.261
Wso2 ≫ Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.377
Wso2 ≫ Open Banking Am Version >= 2.0.0 < 2.0.0.406
Wso2 ≫ Open Banking Iam Version >= 2.0.0 < 2.0.0.426
Wso2 ≫ Traffic Manager Version >= 4.5.0 < 4.5.0.48
Wso2 ≫ Traffic Manager Version >= 4.6.0 < 4.6.0.13
Wso2 ≫ Universal Gateway Version >= 4.5.0 < 4.5.0.49
Wso2 ≫ Universal Gateway Version >= 4.6.0 < 4.6.0.13
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.017 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/