CVE-2026-2445
MEDIUMReflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification
Title source: cnaDescription
The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/
Scores
CVSS v3
6.1
EPSS
0.0015
EPSS Percentile
4.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (12)
WSO2/WSO2 API Control Plane
4.5.0 - 4.5.0.56
WSO2/WSO2 API Control Plane
4.6.0 - 4.6.0.20
WSO2/WSO2 API Manager
4.2.0 - 4.2.0.195
WSO2/WSO2 API Manager
4.3.0 - 4.3.0.106
WSO2/WSO2 API Manager
4.4.0 - 4.4.0.70
WSO2/WSO2 API Manager
4.5.0 - 4.5.0.55
WSO2/WSO2 API Manager
4.6.0 - 4.6.0.19
WSO2/WSO2 Identity Server
6.0.0 - 6.0.0.263
WSO2/WSO2 Identity Server
6.1.0 - 6.1.0.266
WSO2/WSO2 Identity Server
7.0.0 - 7.0.0.144
... and 2 more
Published
Jul 20, 2026
Tracked Since
Jul 20, 2026