PT-2026-55916 · Wso2 · Wso2 Universal Gateway+3

CVE-2026-4249

·

Published

2026-07-06

·

Updated

2026-07-06

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions WSO2 API Manager versions 3.2.0 through 4.7.0 WSO2 Universal Gateway (affected versions not specified) WSO2 Traffic Manager (affected versions not specified) WSO2 API Control Plane (affected versions not specified)
Description The throttling event handling mechanism accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data, causing the API Gateway to crash. This results in a persistent denial of service (DoS) condition, where legitimate API traffic is blocked and all services behind the gateway are unavailable. Recovery from this state requires manual intervention.
Recommendations Update WSO2 API Manager to the fixed patch levels specified in advisory WSO2-2026-5236. Update WSO2 Universal Gateway to the fixed patch levels specified in advisory WSO2-2026-5236. Update WSO2 Traffic Manager to the fixed patch levels specified in advisory WSO2-2026-5236. Update WSO2 API Control Plane to the fixed patch levels specified in advisory WSO2-2026-5236.

Fix

DoS

Improper Neutralization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4249

Affected Products

Wso2 Api Control Plane
Wso2 Api Manager
Wso2 Traffic Manager
Wso2 Universal Gateway