4.7

CVE-2026-3096

Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations.

This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWSO2
≫
Produkt WSO2 API Control Plane
Default Statusunaffected
Version 4.5.0
Version < 4.5.0.54
Status affected
Version 4.6.0
Version < 4.6.0.18
Status affected
HerstellerWSO2
≫
Produkt WSO2 API Manager
Default Statusunaffected
Version 0
Version < 3.2.0
Status unknown
Version 3.2.0
Version < 3.2.0.468
Status affected
Version 3.2.1
Version < 3.2.1.87
Status affected
Version 4.1.0
Version < 4.1.0.252
Status affected
Version 4.2.0
Version < 4.2.0.192
Status affected
Version 4.3.0
Version < 4.3.0.103
Status affected
Version 4.4.0
Version < 4.4.0.67
Status affected
Version 4.5.0
Version < 4.5.0.52
Status affected
Version 4.6.0
Version < 4.6.0.16
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.112
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ed10eef1-636d-4fbe-9993-6890dfa878f8 4.7 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-603 Use of Client-Side Authentication

A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5164/