Description
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.

A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
Published: 2026-08-06
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Event Publisher output adapter causes configuration properties to be logged without proper validation or sanitization. This logging can capture sensitive data, such as user credentials, that should not appear in log files. The result is a leakage of confidential information, classified as a Sensitive Information Disclosure (CWE-532).

Affected Systems

The vulnerability affects several WSO2 products, including WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon Event Publisher Core, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. No specific software versions are listed, so all current releases are potentially impacted.

Risk and Exploitability

The CVSS score of 4.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to gain access to the linked log files (wso2carbon), typically through privileged or local access. Once logged, the attacker can read the exposed credentials or other sensitive content. The attack vector is likely internal or acquired through compromise, rather than a remote exploitation path.

Generated by OpenCVE AI on August 6, 2026 at 09:22 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution


OpenCVE Recommended Actions

  • Apply the vendor patch or follow the instructions provided in the official advisory at https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution.
  • Restrict file system permissions so that only authorized administrators can read the wso2carbon log files.
  • Review and sanitize Event Publisher output adapter configurations to remove irrelevant properties and enable proper logging controls.

Generated by OpenCVE AI on August 6, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 api Control Plane
Wso2 api Manager
Wso2 identity Server
Wso2 identity Server As Key Manager
Wso2 open Banking Am
Wso2 open Banking Iam
Wso2 traffic Manager
Wso2 universal Gateway
CPEs cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_iam:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*
Vendors & Products Wso2 api Control Plane
Wso2 api Manager
Wso2 identity Server
Wso2 identity Server As Key Manager
Wso2 open Banking Am
Wso2 open Banking Iam
Wso2 traffic Manager
Wso2 universal Gateway

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Wso2 wso2 Carbon Event Publisher Core
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam
Wso2 wso2 Traffic Manager
Wso2 wso2 Universal Gateway
Vendors & Products Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Wso2 wso2 Carbon Event Publisher Core
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam
Wso2 wso2 Traffic Manager
Wso2 wso2 Universal Gateway

Thu, 06 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
Title Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wso2 Api Control Plane Api Manager Identity Server Identity Server As Key Manager Open Banking Am Open Banking Iam Traffic Manager Universal Gateway Wso2 Api Control Plane Wso2 Api Manager Wso2 Carbon Event Publisher Core Wso2 Identity Server Wso2 Identity Server As Key Manager Wso2 Open Banking Am Wso2 Open Banking Iam Wso2 Traffic Manager Wso2 Universal Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-06T12:32:09.382Z

Reserved: 2026-01-06T05:51:26.145Z

Link: CVE-2026-0637

cve-icon Vulnrichment

Updated: 2026-08-06T12:32:06.365Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-06T08:16:29.453

Modified: 2026-08-12T19:29:05.020

Link: CVE-2026-0637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:01:10Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File