๐Ÿ” CVE Alert

CVE-2024-6541

MEDIUM 6.8

Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.

CWE CWE-20
Vendor wso2
Product wso2 micro integrator
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for wso2 wso2 micro integrator

Be the first to know when new medium vulnerabilities affecting wso2 wso2 micro integrator are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

WSO2 / WSO2 Micro Integrator
1.2.0 < 1.2.0.163 4.1.0 < 4.1.0.103 4.3.0 < 4.3.0.7
WSO2 / WSO2 Enterprise Integrator
6.6.0 < 6.6.0.205
WSO2 / WSO2 API Manager
3.2.0 < 3.2.0.394 3.2.1 < 3.2.1.21 4.0.0 < 4.0.0.311 4.1.0 < 4.1.0.167 4.2.0 < 4.2.0.110 4.3.0 < 4.3.0.24
WSO2 / WSO2-Synapse
2.1.7.wso2v182 < 2.1.7.wso2v182_93 2.1.7.wso2v143 < 2.1.7.wso2v143_119 2.1.7.wso2v183 < 2.1.7.wso2v183_62 2.1.7.wso2v319 < 2.1.7.wso2v319_7 2.1.7.wso2v227 < 2.1.7.wso2v227_88 2.1.7.wso2v271 < 2.1.7.wso2v271_60 4.0.0.wso2v119 < 4.0.0.wso2v119_3 4.0.0.wso2v105 < 4.0.0.wso2v105_3 4.0.0.wso2v20 < 4.0.0.wso2v20_63

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.docs.wso2.com: https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3520/