Authentication Bypass in WSO2 Products by WSO2
CVE-2024-6541
6.8MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2024-6541?
The vulnerability arises from improperly handled messageContext properties in WSO2 products, allowing authenticated users to access or modify data across distinct system invocations. This flaw presents risks of sensitive information leakage and unauthorized data alterations, heavily reliant on how these properties are deployed within the system. The implications vary, but potential exposure of user data and unintentional data integrity breaches are significant concerns that demand immediate attention.
Affected Version(s)
WSO2 API Manager 3.2.0 < 3.2.0.394
WSO2 API Manager 3.2.1 < 3.2.1.21
WSO2 API Manager 4.0.0 < 4.0.0.311
