8.7
CVE-2026-3415
- EPSS 0.34%
- Veröffentlicht 06.08.2026 22:17:03
- Zuletzt bearbeitet 07.08.2026 18:17:14
- CVE-Watchlists
- Unerledigt
XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service
The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges. Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWSO2
≫
Produkt
WSO2 API Manager
Default Statusunaffected
Version
0
Version <
3.2.0
Status
unknown
Version
3.2.0
Version <
3.2.0.472
Status
affected
Version
3.2.1
Version <
3.2.1.91
Status
affected
Version
4.1.0
Version <
4.1.0.254
Status
affected
Version
4.2.0
Version <
4.2.0.194
Status
affected
Version
4.3.0
Version <
4.3.0.105
Status
affected
Version
4.4.0
Version <
4.4.0.68
Status
affected
Version
4.5.0
Version <
4.5.0.53
Status
affected
Version
4.6.0
Version <
4.6.0.16
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 Universal Gateway
Default Statusunaffected
Version
4.5.0
Version <
4.5.0.53
Status
affected
Version
4.6.0
Version <
4.6.0.16
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 Traffic Manager
Default Statusunaffected
Version
4.5.0
Version <
4.5.0.52
Status
affected
Version
4.6.0
Version <
4.6.0.16
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 API Control Plane
Default Statusunaffected
Version
4.5.0
Version <
4.5.0.54
Status
affected
Version
4.6.0
Version <
4.6.0.17
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 Carbon API Gateway
Default Statusunknown
Version
6.7.206
Version <
6.7.206.594
Status
affected
Version
6.7.210
Version <
6.7.210.95
Status
affected
Version
9.20.74
Version <
9.20.74.398
Status
affected
Version
9.28.116
Version <
9.28.116.412
Status
affected
Version
9.29.120
Version <
9.29.120.228
Status
affected
Version
9.30.67
Version <
9.30.67.158
Status
affected
Version
9.31.86
Version <
9.31.86.147
Status
affected
Version
9.32.147
Version <
9.32.147.38
Status
affected
Version <=
*
Version
9.33.61
Status
unaffected
HerstellerWSO2
≫
Produkt
WSO2 Carbon API Management Implementation
Default Statusunknown
Version
6.7.206
Version <
6.7.206.594
Status
affected
Version
6.7.210
Version <
6.7.210.95
Status
affected
Version
9.20.74
Version <
9.20.74.398
Status
affected
Version
9.28.116
Version <
9.28.116.412
Status
affected
Version
9.29.120
Version <
9.29.120.228
Status
affected
Version
9.30.67
Version <
9.30.67.158
Status
affected
Version
9.31.86
Version <
9.31.86.147
Status
affected
Version
9.32.147
Version <
9.32.147.38
Status
affected
Version <=
*
Version
9.33.61
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.269 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 8.7 | 2.3 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
|
CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5001/