{"api_version":"1","generated_at":"2026-07-23T10:05:17+00:00","cve":"CVE-2026-2445","urls":{"html":"https://cve.report/CVE-2026-2445","api":"https://cve.report/api/cve/CVE-2026-2445.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-2445","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-2445"},"summary":{"title":"Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification","description":"The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads.\n\nAn attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag.","state":"PUBLISHED","assigner":"WSO2","published_at":"2026-07-20 08:16:30","updated_at":"2026-07-20 15:16:36"},"problem_types":["CWE-79","CWE-79 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":[{"version":"3.1","source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","type":"Secondary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/","name":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/","refsource":"ed10eef1-636d-4fbe-9993-6890dfa878f8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-2445","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2445","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"WSO2","product":"WSO2 API Manager","version":"affected 4.2.0 4.2.0.195 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 API Manager","version":"affected 4.3.0 4.3.0.106 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 API Manager","version":"affected 4.4.0 4.4.0.70 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 API Manager","version":"affected 4.5.0 4.5.0.55 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 API Manager","version":"affected 4.6.0 4.6.0.19 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 API Control Plane","version":"affected 4.5.0 4.5.0.56 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 API Control Plane","version":"affected 4.6.0 4.6.0.20 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 Identity Server","version":"affected 6.0.0 6.0.0.263 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 Identity Server","version":"affected 6.1.0 6.1.0.266 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 Identity Server","version":"affected 7.0.0 7.0.0.144 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 Identity Server","version":"affected 7.1.0 7.1.0.53 custom","platforms":[]},{"source":"CNA","vendor":"WSO2","product":"WSO2 Identity Server","version":"affected 7.2.0 7.2.0.12 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/#solution","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Maneesha Dewmine","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"2445","cve":"CVE-2026-2445","epss":"0.001490000","percentile":"0.044980000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-2445","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-20T13:52:47.520347Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-20T13:52:59.977Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"WSO2 API Manager","vendor":"WSO2","versions":[{"lessThan":"4.2.0.195","status":"affected","version":"4.2.0","versionType":"custom"},{"lessThan":"4.3.0.106","status":"affected","version":"4.3.0","versionType":"custom"},{"lessThan":"4.4.0.70","status":"affected","version":"4.4.0","versionType":"custom"},{"lessThan":"4.5.0.55","status":"affected","version":"4.5.0","versionType":"custom"},{"lessThan":"4.6.0.19","status":"affected","version":"4.6.0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"WSO2 API Control Plane","vendor":"WSO2","versions":[{"lessThan":"4.5.0.56","status":"affected","version":"4.5.0","versionType":"custom"},{"lessThan":"4.6.0.20","status":"affected","version":"4.6.0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"WSO2 Identity Server","vendor":"WSO2","versions":[{"lessThan":"6.0.0.263","status":"affected","version":"6.0.0","versionType":"custom"},{"lessThan":"6.1.0.266","status":"affected","version":"6.1.0","versionType":"custom"},{"lessThan":"7.0.0.144","status":"affected","version":"7.0.0","versionType":"custom"},{"lessThan":"7.1.0.53","status":"affected","version":"7.1.0","versionType":"custom"},{"lessThan":"7.2.0.12","status":"affected","version":"7.2.0","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.2.0.195","versionStartIncluding":"4.2.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.3.0.106","versionStartIncluding":"4.3.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.4.0.70","versionStartIncluding":"4.4.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.0.55","versionStartIncluding":"4.5.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.6.0.19","versionStartIncluding":"4.6.0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.0.56","versionStartIncluding":"4.5.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*","versionEndExcluding":"4.6.0.20","versionStartIncluding":"4.6.0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*","versionEndExcluding":"6.0.0.263","versionStartIncluding":"6.0.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.0.266","versionStartIncluding":"6.1.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.0.144","versionStartIncluding":"7.0.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.0.53","versionStartIncluding":"7.1.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.0.12","versionStartIncluding":"7.2.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"reporter","value":"Maneesha Dewmine"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads.\n\nAn attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag."}],"value":"The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads.\n\nAn attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag."}],"impacts":[{"capecId":"CAPEC-22","descriptions":[{"lang":"en","value":"CAPEC-22 CAPEC-22: Cross-Site Scripting"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-20T08:06:39.095Z","orgId":"ed10eef1-636d-4fbe-9993-6890dfa878f8","shortName":"WSO2"},"references":[{"tags":["vendor-advisory"],"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span style=\"background-color: transparent;\">Follow the instructions given on </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/#solution\"><span style=\"background-color: transparent;\">https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/#solution</span></a> <br>"}],"value":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5059/#solution"}],"source":{"advisory":"WSO2-2026-5059","discovery":"EXTERNAL"},"title":"Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"ed10eef1-636d-4fbe-9993-6890dfa878f8","assignerShortName":"WSO2","cveId":"CVE-2026-2445","datePublished":"2026-07-20T08:06:39.095Z","dateReserved":"2026-02-13T07:48:55.362Z","dateUpdated":"2026-07-20T13:52:59.977Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-20 08:16:30","lastModifiedDate":"2026-07-20 15:16:36","problem_types":["CWE-79","CWE-79 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"],"metrics":{"cvssMetricV31":[{"source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-20T13:52:47.520347Z","id":"CVE-2026-2445","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"2445","Ordinal":"1","Title":"Reflected Cross-Site Scripting via URL Parameter in Multiple WSO","CVE":"CVE-2026-2445","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"2445","Ordinal":"1","NoteData":"The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads.\n\nAn attacker can leverage this vulnerability to cause the user's browser to redirect to a malicious website, modify the user interface of the webpage, or retrieve sensitive information from the browser. However, the impact is mitigated for session hijacking as all session-related sensitive cookies are protected by the httpOnly flag.","Type":"Description","Title":"Reflected Cross-Site Scripting via URL Parameter in Multiple WSO"}]}}}