Vulnerability in API Publisher Component of WSO2 Affects HMAC Validation
CVE-2026-3416

5.9MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
3 September 2026

What is CVE-2026-3416?

The API Publisher component of WSO2 utilizes a non-cryptographic pseudorandom number generator (PRNG) to generate shared secrets intended for Webhook HMAC validation. This method fails to provide adequate entropy required for sensitive security operations, making it possible for an attacker to predict future shared secrets. By exploiting this vulnerability, attackers can forge event payloads equipped with valid HMAC signatures, successfully circumventing the authenticity verification conducted by the API Gateway. Such exploitation could lead to unauthorized event injections, data manipulation, or potential compromise of downstream systems.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.53

WSO2 API Manager 4.1.0 < 4.1.0.253

WSO2 API Manager 4.2.0 < 4.2.0.193

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.