Insufficient HTML Sanitization in Publisher Portal and Developer Portal by WSO2
CVE-2026-4103

6.4MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
14 September 2026

What is CVE-2026-4103?

The Publisher Portal and Developer Portal from WSO2 exhibit insufficient HTML sanitization, allowing untrusted user input to be displayed without appropriate encoding or neutralization. This oversight makes it possible for malicious JavaScript code to be injected and executed when API documents are accessed. Users who can view API documentation through these portals are at risk, as successful exploitation may enable attackers to execute scripts within the user's browser context. Consequently, this could allow unauthorized actions to be carried out on behalf of the user, depending on their session privileges.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.55

WSO2 API Control Plane 4.6.0 < 4.6.0.19

WSO2 API Manager 3.2.0 < 3.2.0.470

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

San Gil from Security Office
.