PT-2026-52667 · Wso2 · Wso2 Api Manager

CVE-2026-2053

·

Published

2026-06-26

·

Updated

2026-06-27

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WSO2 API Manager (affected versions not specified)
Description The message flow component fails to sufficiently validate or restrict user-controlled input within WS-Addressing headers. This allows an unauthenticated attacker to manipulate these headers to specify arbitrary destinations for server-initiated requests, leading to Server-Side Request Forgery (SSRF). SSRF is a technique where an attacker induces a server-side application to make requests to an unintended location. This can enable unauthorized access to internal network resources or services that are typically inaccessible from external networks.
Recommendations Apply the latest security patches from WSO2.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2053

Affected Products

Wso2 Api Manager