Description
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations.

This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.
Published: 2026-09-10
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Phishing and Credential Theft
Action: Patch
AI Analysis

Impact

The web portals of WSO2 API Control Plane and WSO2 API Manager allow external links to be opened in a new browser tab. In certain configurations the originating window retains access to the newly opened page, enabling interaction between the two browser contexts when navigating to external destinations. If a user clicks a malicious external link, after the new tab has opened, potentially redirecting the user to phishing pages, stealing credentials, or executing other unauthorized actions within the trusted site.

Affected Systems

WSO2 API Control Plane and WSO2 API Manager are affected. No specific version range is listed, so all current builds of these products should be considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity. The attack requires user interaction—clicking a malicious external link that opens in a new tab—after which the attacker can interact with the original window. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known exploitation yet, but the subversion of the trusted context remains a real threat. Given the moderate CVSS and the user-interaction requirement, the overall risk is moderate awaiting a fix.

Generated by OpenCVE AI on September 10, 2026 at 22:52 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5164/#solution


OpenCVE Recommended Actions

  • Apply the vendor‑provided patch following the instructions at https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5164/#solution
  • Disable external links opening in new browser tabs or enforce strict same‑origin policies in the portal configuration to prevent cross‑context interaction
  • Sanitize all user‑generated URLs to ensure input validation, mitigating the risk of malicious links manipulating the trusted window

Generated by OpenCVE AI on September 10, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 api Control Plane
Wso2 api Manager
Vendors & Products Wso2 api Control Plane
Wso2 api Manager

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.
Title Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
First Time appeared Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Weaknesses CWE-20
CWE-603
CPEs cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

Wso2 Api Control Plane Api Manager Wso2 Api Control Plane Wso2 Api Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-09-10T20:40:28.687Z

Reserved: 2026-02-24T06:39:32.867Z

Link: CVE-2026-3096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T21:17:27.090

Modified: 2026-09-10T21:17:27.090

Link: CVE-2026-3096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:30:07Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-603

    Use of Client-Side Authentication