Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure
Summary
| CVE | CVE-2024-10302 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:26 UTC |
| Updated | 2026-08-06 15:31:57 UTC |
| Description | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious or malformed data injected during signup could be processed by other parts of the application, potentially enabling attacks such as content manipulation, redirection, user interface inconsistencies, unauthorized actions, and data exposure. The actual impact depends on how the compromised data is consumed and the privileges associated with the affected users. |
Risk And Classification
Primary CVSS: v3.1 4 MEDIUM from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS: 0.001730000 probability, percentile 0.069430000 (date 2026-08-08)
Problem Types: CWE-20 | CWE-20 CWE-20 Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 4 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 4 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 API Control Plane | affected 4.5.0 4.5.0.10 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.5.0 4.5.0.9 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.5.0 4.5.0.9 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | unknown 3.1.0 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.1.0 3.1.0.331 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.2.0 3.2.0.427 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.2.1 3.2.1.39 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.0.0 4.0.0.318 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.1.0 4.1.0.200 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.2.0 4.2.0.138 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.3.0 4.3.0.51 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.5.0 4.5.0.9 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking IAM | unknown 2.0.0 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking IAM | affected 2.0.0 2.0.0.400 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | unknown 5.10.0 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | affected 5.10.0 5.10.0.351 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | unknown 5.10.0 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.10.0 5.10.0.358 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.11.0 5.11.0.379 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | affected 1.4.1 1.4.1.72 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | affected 1.4.72 1.4.72.68 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | affected 1.4.100 1.4.100.8 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | affected 1.4.102 1.4.102.2 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | affected 1.7.2 1.7.2.4 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | affected 1.8.107 1.8.107.2 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | affected 1.8.108 1.8.108.4 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | unaffected 1.6.380 1.6.* custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Recovery Management | unaffected 1.8.109 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3740/#solution
There are currently no legacy QID mappings associated with this CVE.