CVE-2026-2053
Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.
| CWE | CWE-918 |
| Vendor | wso2 |
| Product | wso2 api manager |
| Published | Jun 26, 2026 |
Get instant alerts for wso2 wso2 api manager
Be the first to know when new high vulnerabilities affecting wso2 wso2 api manager are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L