Information Disclosure Vulnerability in WSO2 Event Publisher
CVE-2026-0637

4.4MEDIUM

What is CVE-2026-0637?

An information disclosure vulnerability exists in WSO2 Event Publisher due to improper handling of output adapter configurations. When irrelevant properties are specified in the output adapter configuration, the system logs these properties without adequate validation or sanitization. This could inadvertently expose sensitive information, including user credentials, to any malicious user who has access to the 'wso2carbon' log files, leading to potential unauthorized access and data breaches. Proper configuration and validation practices are essential to mitigate this risk.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.50

WSO2 API Control Plane 4.6.0 < 4.6.0.14

WSO2 API Manager 3.1.0 < 3.1.0.357

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.