Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-2053: WSO2 API Manager Allows Unauthenticated Destination Control

CVE-2026-2053
Summary

The WSO2 API Manager's message flow component does not properly check user input in certain headers. This allows an attacker to control where internal server requests go, potentially giving them access to internal resources or services they shouldn't have access to. To protect your system, update the WSO2 API Manager to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
wso2 api_manager >= 3.1.0, < 3.1.0.360
>= 3.2.0, < 3.2.0.465
>= 3.2.1, < 3.2.1.84
>= 4.0.0, < 4.0.0.385
>= 4.2.0, < 4.2.0.189
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
Original title
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an ...
Original description
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests.

Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.
nvd CVSS3.1 8.3
Vulnerability type
CWE-918 Server-Side Request Forgery (SSRF)
Published: 26 Jun 2026 · Updated: 20 Jul 2026 · First seen: 26 Jun 2026