XML External Entity Vulnerability in WSO2 SchemaValidator Mediator
CVE-2026-3415

8.7HIGH

What is CVE-2026-3415?

The vulnerability in the WSO2 SchemaValidator Mediator arises from the XML and schema validation functionalities, which improperly handle external entity resolution in XML input. When an attacker sends specially crafted XML payloads during validation flows, they can exploit this behavior if they possess sufficient privileges. This exploitation could grant attackers the ability to read sensitive files on the server or initiate unauthorized outbound requests. Additionally, the excessive resource consumption from parsing these payloads could potentially disrupt service availability further impacting the product's performance.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.54

WSO2 API Control Plane 4.6.0 < 4.6.0.17

WSO2 API Manager 3.2.0 < 3.2.0.472

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.