4.7
CVE-2026-3096
- EPSS 0.21%
- Veröffentlicht 10.09.2026 20:40:28
- Zuletzt bearbeitet 18.09.2026 19:13:15
- Erkennungen
Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWSO2
≫
Produkt
WSO2 API Control Plane
Default Statusunaffected
Version
4.5.0
Version <
4.5.0.54
Status
affected
Version
4.6.0
Version <
4.6.0.18
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 API Manager
Default Statusunaffected
Version
0
Version <
3.2.0
Status
unknown
Version
3.2.0
Version <
3.2.0.468
Status
affected
Version
3.2.1
Version <
3.2.1.87
Status
affected
Version
4.1.0
Version <
4.1.0.252
Status
affected
Version
4.2.0
Version <
4.2.0.192
Status
affected
Version
4.3.0
Version <
4.3.0.103
Status
affected
Version
4.4.0
Version <
4.4.0.67
Status
affected
Version
4.5.0
Version <
4.5.0.52
Status
affected
Version
4.6.0
Version <
4.6.0.16
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.112 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 4.7 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-603 Use of Client-Side Authentication
A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5164/