Web Portal External Link Manipulation Vulnerability in WSO2 Products
CVE-2026-3096

4.7MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
10 September 2026

What is CVE-2026-3096?

The vulnerability arises due to the ability of the product's web portals to open external links in new browser tabs, thereby maintaining access to the originating application window. This can lead to scenarios where an attacker exploits this behavior, allowing for interactions between the trusted application and malicious external pages. Such manipulation can redirect users to phishing attempts or facilitate unauthorized actions, compromising user credentials and sensitive information.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.54

WSO2 API Control Plane 4.6.0 < 4.6.0.18

WSO2 API Manager 3.2.0 < 3.2.0.468

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.