Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Summary
| CVE | CVE-2026-0637 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:29 UTC |
| Updated | 2026-08-06 15:31:57 UTC |
| Description | When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access. |
Risk And Classification
Primary CVSS: v3.1 4.4 MEDIUM from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.001130000 probability, percentile 0.016540000 (date 2026-08-08)
Problem Types: CWE-532 | CWE-532 CWE-532: Insertion of Sensitive Information into Log Files
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 4.4 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 4.4 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 API Manager | unknown 3.1.0 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.1.0 3.1.0.357 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.2.0 3.2.0.465 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.2.1 3.2.1.84 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.1.0 4.1.0.249 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.2.0 4.2.0.189 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.3.0 4.3.0.100 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.4.0 4.4.0.64 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.5.0 4.5.0.49 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.6.0 4.6.0.13 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | unknown 4.5.0 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.5.0 4.5.0.48 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.6.0 4.6.0.13 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | unknown 4.5.0 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.5.0 4.5.0.50 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.6.0 4.6.0.14 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | unknown 4.5.0 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.5.0 4.5.0.49 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.6.0 4.6.0.13 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | unknown 5.10.0 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.10.0 5.10.0.386 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.11.0 5.11.0.433 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 6.0.0 6.0.0.260 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 6.1.0 6.1.0.261 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.0.0 7.0.0.139 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.1.0 7.1.0.47 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.2.0 7.2.0.8 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | unknown 5.10.0 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | affected 5.10.0 5.10.0.377 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking IAM | unknown 2.0.0 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking IAM | affected 2.0.0 2.0.0.426 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking AM | unknown 2.0.0 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking AM | affected 2.0.0 2.0.0.406 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.24 5.2.24.11 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.26 5.2.26.24 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.27 5.2.27.7 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.41 5.2.41.8 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.45 5.2.45.2 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.50 5.2.50.3 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.57 5.2.57.12 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.58 5.2.58.3 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.61 5.2.61.4 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.2.64 5.2.64.1 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.3.5 5.3.5.10 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.3.11 5.3.11.7 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.3.15 5.3.15.6 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.3.20 5.3.20.3 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | affected 5.3.27 5.3.27.1 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Event Publisher Core | unaffected x * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution
There are currently no legacy QID mappings associated with this CVE.