Impact
The vulnerability arises in the self‑signup flow of a range of WSO2 products where user-generated input is not adequately validated or sanitized before being stored in user claims. This lack of input validation permits the injection of arbitrary data into claims, which downstream components may process without integrity checks, opening the door to content manipulation, redirection attacks, user interface inconsistencies, unauthorized actions, and the unintended disclosure of confidential information. The severity depends on how the injected data is later used and on the privileges granted to the affected users, but the weakness fundamentally undermines the integrity and confidentiality of user data.
Affected Systems
Products affected include WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon Identity Recovery Management, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. All versions prior to the patches identified by WSO2 in security advisory 2026/WSO2-2024-3740 are vulnerable; the specific affected versions are detailed in that advisory.
Risk and Exploitability
The CVSS score of 4 indicates a moderate risk level. No EPSS score is available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread, documented exploitation at this time. Attackers can exploit this weakness by submitting crafted payloads during the signup process, but the success of any subsequent attack depends on additional application logic that consumes the manipulated claims. The vulnerability is publicly documented and the advisory recommends applying the vendor’s fix to mitigate the risk.
OpenCVE Enrichment