Vulnerability in API Publisher Component of WSO2 Affects HMAC Validation
CVE-2026-3416
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 3 September 2026
What is CVE-2026-3416?
The API Publisher component of WSO2 utilizes a non-cryptographic pseudorandom number generator (PRNG) to generate shared secrets intended for Webhook HMAC validation. This method fails to provide adequate entropy required for sensitive security operations, making it possible for an attacker to predict future shared secrets. By exploiting this vulnerability, attackers can forge event payloads equipped with valid HMAC signatures, successfully circumventing the authenticity verification conducted by the API Gateway. Such exploitation could lead to unauthorized event injections, data manipulation, or potential compromise of downstream systems.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.53
WSO2 API Manager 4.1.0 < 4.1.0.253
WSO2 API Manager 4.2.0 < 4.2.0.193
