CVE-2026-0637

EUVD-2026-53820
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.

A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.64%
Affected Products (NVD)
VendorProductVersion
wso2api_control_plane
4.5.0 ≤
𝑥
< 4.5.0.50
wso2api_control_plane
4.6.0 ≤
𝑥
< 4.6.0.14
wso2api_manager
3.1.0 ≤
𝑥
< 3.1.0.357
wso2api_manager
3.2.0 ≤
𝑥
< 3.2.0.465
wso2api_manager
3.2.1 ≤
𝑥
< 3.2.1.84
wso2api_manager
4.1.0 ≤
𝑥
< 4.1.0.249
wso2api_manager
4.2.0 ≤
𝑥
< 4.2.0.189
wso2api_manager
4.3.0 ≤
𝑥
< 4.3.0.100
wso2api_manager
4.4.0 ≤
𝑥
< 4.4.0.64
wso2api_manager
4.5.0 ≤
𝑥
< 4.5.0.49
wso2api_manager
4.6.0 ≤
𝑥
< 4.6.0.13
wso2identity_server
5.10.0 ≤
𝑥
< 5.10.0.386
wso2identity_server
5.11.0 ≤
𝑥
< 5.11.0.433
wso2identity_server
6.0.0 ≤
𝑥
< 6.0.0.260
wso2identity_server
6.1.0 ≤
𝑥
< 6.1.0.261
wso2identity_server_as_key_manager
5.10.0 ≤
𝑥
< 5.10.0.377
wso2open_banking_am
2.0.0 ≤
𝑥
< 2.0.0.406
wso2open_banking_iam
2.0.0 ≤
𝑥
< 2.0.0.426
wso2traffic_manager
4.5.0 ≤
𝑥
< 4.5.0.48
wso2traffic_manager
4.6.0 ≤
𝑥
< 4.6.0.13
wso2universal_gateway
4.5.0 ≤
𝑥
< 4.5.0.49
wso2universal_gateway
4.6.0 ≤
𝑥
< 4.6.0.13
𝑥
= Vulnerable software versions