Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-2053

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 9.8%
CVSS Severity
CVSS v3 Score 8.3
Products affected by CVE-2026-2053
  • Wso2 » Api Manager » Version: 3.1.0
    cpe:2.3:a:wso2:api_manager:3.1.0
  • Wso2 » Api Manager » Version: 3.1.0.181
    cpe:2.3:a:wso2:api_manager:3.1.0.181
  • Wso2 » Api Manager » Version: 3.1.0.278
    cpe:2.3:a:wso2:api_manager:3.1.0.278
  • Wso2 » Api Manager » Version: 3.1.0.293
    cpe:2.3:a:wso2:api_manager:3.1.0.293
  • Wso2 » Api Manager » Version: 3.1.0.322
    cpe:2.3:a:wso2:api_manager:3.1.0.322
  • Wso2 » Api Manager » Version: 3.1.0.331
    cpe:2.3:a:wso2:api_manager:3.1.0.331
  • Wso2 » Api Manager » Version: 3.1.0.345
    cpe:2.3:a:wso2:api_manager:3.1.0.345
  • Wso2 » Api Manager » Version: 3.1.0.347
    cpe:2.3:a:wso2:api_manager:3.1.0.347
  • Wso2 » Api Manager » Version: 3.1.0.349
    cpe:2.3:a:wso2:api_manager:3.1.0.349
  • Wso2 » Api Manager » Version: 3.1.0.351
    cpe:2.3:a:wso2:api_manager:3.1.0.351
  • Wso2 » Api Manager » Version: 3.1.0.356
    cpe:2.3:a:wso2:api_manager:3.1.0.356
  • Wso2 » Api Manager » Version: 3.2.0
    cpe:2.3:a:wso2:api_manager:3.2.0
  • Wso2 » Api Manager » Version: 3.2.0.226
    cpe:2.3:a:wso2:api_manager:3.2.0.226
  • Wso2 » Api Manager » Version: 3.2.0.278
    cpe:2.3:a:wso2:api_manager:3.2.0.278
  • Wso2 » Api Manager » Version: 3.2.0.368
    cpe:2.3:a:wso2:api_manager:3.2.0.368
  • Wso2 » Api Manager » Version: 3.2.0.384
    cpe:2.3:a:wso2:api_manager:3.2.0.384
  • Wso2 » Api Manager » Version: 3.2.0.397
    cpe:2.3:a:wso2:api_manager:3.2.0.397
  • Wso2 » Api Manager » Version: 3.2.0.401
    cpe:2.3:a:wso2:api_manager:3.2.0.401
  • Wso2 » Api Manager » Version: 3.2.0.408
    cpe:2.3:a:wso2:api_manager:3.2.0.408
  • Wso2 » Api Manager » Version: 3.2.0.415
    cpe:2.3:a:wso2:api_manager:3.2.0.415
  • Wso2 » Api Manager » Version: 3.2.0.422
    cpe:2.3:a:wso2:api_manager:3.2.0.422
  • Wso2 » Api Manager » Version: 3.2.0.427
    cpe:2.3:a:wso2:api_manager:3.2.0.427
  • Wso2 » Api Manager » Version: 3.2.0.432
    cpe:2.3:a:wso2:api_manager:3.2.0.432
  • Wso2 » Api Manager » Version: 3.2.0.433
    cpe:2.3:a:wso2:api_manager:3.2.0.433
  • Wso2 » Api Manager » Version: 3.2.0.434
    cpe:2.3:a:wso2:api_manager:3.2.0.434
  • Wso2 » Api Manager » Version: 3.2.0.435
    cpe:2.3:a:wso2:api_manager:3.2.0.435
  • Wso2 » Api Manager » Version: 3.2.0.446
    cpe:2.3:a:wso2:api_manager:3.2.0.446
  • Wso2 » Api Manager » Version: 3.2.0.450
    cpe:2.3:a:wso2:api_manager:3.2.0.450
  • Wso2 » Api Manager » Version: 3.2.0.453
    cpe:2.3:a:wso2:api_manager:3.2.0.453
  • Wso2 » Api Manager » Version: 3.2.0.455
    cpe:2.3:a:wso2:api_manager:3.2.0.455
  • Wso2 » Api Manager » Version: 3.2.0.460
    cpe:2.3:a:wso2:api_manager:3.2.0.460
  • Wso2 » Api Manager » Version: 3.2.1
    cpe:2.3:a:wso2:api_manager:3.2.1
  • Wso2 » Api Manager » Version: 3.2.1.16
    cpe:2.3:a:wso2:api_manager:3.2.1.16
  • Wso2 » Api Manager » Version: 3.2.1.27
    cpe:2.3:a:wso2:api_manager:3.2.1.27
  • Wso2 » Api Manager » Version: 3.2.1.32
    cpe:2.3:a:wso2:api_manager:3.2.1.32
  • Wso2 » Api Manager » Version: 3.2.1.39
    cpe:2.3:a:wso2:api_manager:3.2.1.39
  • Wso2 » Api Manager » Version: 3.2.1.42
    cpe:2.3:a:wso2:api_manager:3.2.1.42
  • Wso2 » Api Manager » Version: 3.2.1.52
    cpe:2.3:a:wso2:api_manager:3.2.1.52
  • Wso2 » Api Manager » Version: 3.2.1.53
    cpe:2.3:a:wso2:api_manager:3.2.1.53
  • Wso2 » Api Manager » Version: 3.2.1.54
    cpe:2.3:a:wso2:api_manager:3.2.1.54
  • Wso2 » Api Manager » Version: 3.2.1.55
    cpe:2.3:a:wso2:api_manager:3.2.1.55
  • Wso2 » Api Manager » Version: 3.2.1.66
    cpe:2.3:a:wso2:api_manager:3.2.1.66
  • Wso2 » Api Manager » Version: 3.2.1.69
    cpe:2.3:a:wso2:api_manager:3.2.1.69
  • Wso2 » Api Manager » Version: 3.2.1.70
    cpe:2.3:a:wso2:api_manager:3.2.1.70
  • Wso2 » Api Manager » Version: 3.2.1.73
    cpe:2.3:a:wso2:api_manager:3.2.1.73
  • Wso2 » Api Manager » Version: 3.2.1.74
    cpe:2.3:a:wso2:api_manager:3.2.1.74
  • Wso2 » Api Manager » Version: 3.2.1.79
    cpe:2.3:a:wso2:api_manager:3.2.1.79
  • Wso2 » Api Manager » Version: 4.0.0
    cpe:2.3:a:wso2:api_manager:4.0.0
  • Wso2 » Api Manager » Version: 4.0.0.168
    cpe:2.3:a:wso2:api_manager:4.0.0.168
  • Wso2 » Api Manager » Version: 4.0.0.217
    cpe:2.3:a:wso2:api_manager:4.0.0.217
  • Wso2 » Api Manager » Version: 4.0.0.280
    cpe:2.3:a:wso2:api_manager:4.0.0.280
  • Wso2 » Api Manager » Version: 4.0.0.293
    cpe:2.3:a:wso2:api_manager:4.0.0.293
  • Wso2 » Api Manager » Version: 4.0.0.305
    cpe:2.3:a:wso2:api_manager:4.0.0.305
  • Wso2 » Api Manager » Version: 4.0.0.310
    cpe:2.3:a:wso2:api_manager:4.0.0.310
  • Wso2 » Api Manager » Version: 4.0.0.318
    cpe:2.3:a:wso2:api_manager:4.0.0.318
  • Wso2 » Api Manager » Version: 4.0.0.319
    cpe:2.3:a:wso2:api_manager:4.0.0.319
  • Wso2 » Api Manager » Version: 4.0.0.355
    cpe:2.3:a:wso2:api_manager:4.0.0.355
  • Wso2 » Api Manager » Version: 4.0.0.368
    cpe:2.3:a:wso2:api_manager:4.0.0.368
  • Wso2 » Api Manager » Version: 4.0.0.370
    cpe:2.3:a:wso2:api_manager:4.0.0.370
  • Wso2 » Api Manager » Version: 4.0.0.373
    cpe:2.3:a:wso2:api_manager:4.0.0.373
  • Wso2 » Api Manager » Version: 4.0.0.375
    cpe:2.3:a:wso2:api_manager:4.0.0.375
  • Wso2 » Api Manager » Version: 4.0.0.381
    cpe:2.3:a:wso2:api_manager:4.0.0.381
  • Wso2 » Api Manager » Version: 4.2.0
    cpe:2.3:a:wso2:api_manager:4.2.0
  • Wso2 » Api Manager » Version: 4.2.0.100
    cpe:2.3:a:wso2:api_manager:4.2.0.100
  • Wso2 » Api Manager » Version: 4.2.0.108
    cpe:2.3:a:wso2:api_manager:4.2.0.108
  • Wso2 » Api Manager » Version: 4.2.0.127
    cpe:2.3:a:wso2:api_manager:4.2.0.127
  • Wso2 » Api Manager » Version: 4.2.0.138
    cpe:2.3:a:wso2:api_manager:4.2.0.138
  • Wso2 » Api Manager » Version: 4.2.0.144
    cpe:2.3:a:wso2:api_manager:4.2.0.144
  • Wso2 » Api Manager » Version: 4.2.0.150
    cpe:2.3:a:wso2:api_manager:4.2.0.150
  • Wso2 » Api Manager » Version: 4.2.0.153
    cpe:2.3:a:wso2:api_manager:4.2.0.153
  • Wso2 » Api Manager » Version: 4.2.0.156
    cpe:2.3:a:wso2:api_manager:4.2.0.156
  • Wso2 » Api Manager » Version: 4.2.0.157
    cpe:2.3:a:wso2:api_manager:4.2.0.157
  • Wso2 » Api Manager » Version: 4.2.0.164
    cpe:2.3:a:wso2:api_manager:4.2.0.164
  • Wso2 » Api Manager » Version: 4.2.0.169
    cpe:2.3:a:wso2:api_manager:4.2.0.169
  • Wso2 » Api Manager » Version: 4.2.0.171
    cpe:2.3:a:wso2:api_manager:4.2.0.171
  • Wso2 » Api Manager » Version: 4.2.0.173
    cpe:2.3:a:wso2:api_manager:4.2.0.173
  • Wso2 » Api Manager » Version: 4.2.0.176
    cpe:2.3:a:wso2:api_manager:4.2.0.176
  • Wso2 » Api Manager » Version: 4.2.0.178
    cpe:2.3:a:wso2:api_manager:4.2.0.178
  • Wso2 » Api Manager » Version: 4.2.0.179
    cpe:2.3:a:wso2:api_manager:4.2.0.179
  • Wso2 » Api Manager » Version: 4.2.0.182
    cpe:2.3:a:wso2:api_manager:4.2.0.182
  • Wso2 » Api Manager » Version: 4.2.0.184
    cpe:2.3:a:wso2:api_manager:4.2.0.184
  • Wso2 » Api Manager » Version: 4.2.0.80
    cpe:2.3:a:wso2:api_manager:4.2.0.80


Contact Us

Shodan ® - All rights reserved