Description
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.

A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
Published: 2026-08-06
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Event Publisher output adapter causes configuration properties to be logged without proper validation or sanitization. This logging can capture sensitive data, such as user credentials, that should not appear in log files. The result is a leakage of confidential information, classified as a Sensitive Information Disclosure (CWE-532).

Affected Systems

The vulnerability affects several WSO2 products, including WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon Event Publisher Core, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. No specific software versions are listed, so all current releases are potentially impacted.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to gain access to the linked log files (wso2carbon), typically through privileged or local access. Once logged, the attacker can read the exposed credentials or other sensitive content. The attack vector is likely internal or acquired through compromise, rather than a remote exploitation path.

Generated by OpenCVE AI on August 6, 2026 at 09:22 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution


OpenCVE Recommended Actions

  • Apply the vendor patch or follow the instructions provided in the official advisory at https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution.
  • Restrict file system permissions so that only authorized administrators can read the wso2carbon log files.
  • Review and sanitize Event Publisher output adapter configurations to remove irrelevant properties and enable proper logging controls.

Generated by OpenCVE AI on August 6, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
Title Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-06T12:32:09.382Z

Reserved: 2026-01-06T05:51:26.145Z

Link: CVE-2026-0637

cve-icon Vulnrichment

Updated: 2026-08-06T12:32:06.365Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T09:30:02Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File