CVE-2026-2445

MEDIUM

Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification

Title source: cna
STIX 2.1

Description

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag.

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0015
EPSS Percentile 4.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (12)
WSO2/WSO2 API Control Plane 4.5.0 - 4.5.0.56
WSO2/WSO2 API Control Plane 4.6.0 - 4.6.0.20
WSO2/WSO2 API Manager 4.2.0 - 4.2.0.195
WSO2/WSO2 API Manager 4.3.0 - 4.3.0.106
WSO2/WSO2 API Manager 4.4.0 - 4.4.0.70
WSO2/WSO2 API Manager 4.5.0 - 4.5.0.55
WSO2/WSO2 API Manager 4.6.0 - 4.6.0.19
WSO2/WSO2 Identity Server 6.0.0 - 6.0.0.263
WSO2/WSO2 Identity Server 6.1.0 - 6.1.0.266
WSO2/WSO2 Identity Server 7.0.0 - 7.0.0.144
... and 2 more
Published Jul 20, 2026
Tracked Since Jul 20, 2026