Description
Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API documents are viewed.

Successful exploitation may result in the execution of malicious scripts within the user's browser context when viewing API documentation. Users with permissions to access the API documentation through these portals may be impacted, potentially allowing attackers to perform actions on behalf of the user, depending on their session privileges.
Published: 2026-09-14
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Execution of arbitrary JavaScript in users’ browsers via XSS when viewing API documentation
Action: Apply Patch
AI Analysis

Impact

Insufficient HTML sanitization in the Publisher Portal and Developer Portal permits untrusted content to be rendered without proper encoding or neutralization, enabling the injection and execution of malicious JavaScript. This cross‑site scripting flaw can allow an attacker to run arbitrary scripts in the context of any user who views the affected API documentation, potentially performing actions on the user’s behalf depending on the session’s privileges.

Affected Systems

The vulnerability affects WSO2 API Control Plane and WSO2 API Manager through their Publisher and Developer Portals. No specific product versions are listed, so all releases using these portals are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. The EPSS score of 0.0018 (< 1%) indicates a very low exploitation probability, and the flaw is not listed in the CISA KEV catalog. Successful exploitation requires a user with permission to access the API documentation where the untrusted input is embedded. Attackers may gain the ability to execute malicious scripts on behalf of that user, potentially leading to data theft, session hijack, or other privilege‑based attacks. While no explicit exploit code is disclosed, the flaw can be triggered through crafted API documentation content.

Generated by OpenCVE AI on September 21, 2026 at 00:32 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-4844/#solution


OpenCVE Recommended Actions

  • Apply the vendor‑released patch or update following the instructions cited in the WSO2 security advisory
  • If a patch cannot be applied immediately, enforce strict content sanitization or remove untrusted input from API documentation before rendering
  • Limit access to the Publisher and Developer Portals to trusted users and review user permissions regularly

Generated by OpenCVE AI on September 21, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 api Control Plane
Wso2 api Manager
Vendors & Products Wso2 api Control Plane
Wso2 api Manager

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API documents are viewed. Successful exploitation may result in the execution of malicious scripts within the user's browser context when viewing API documentation. Users with permissions to access the API documentation through these portals may be impacted, potentially allowing attackers to perform actions on behalf of the user, depending on their session privileges.
Title Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution
First Time appeared Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Weaknesses CWE-79
CPEs cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Wso2 Api Control Plane Api Manager Wso2 Api Control Plane Wso2 Api Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-09-14T19:22:59.838Z

Reserved: 2026-03-13T06:07:54.085Z

Link: CVE-2026-4103

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:11.374Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:11.710

Modified: 2026-09-18T19:13:15.430

Link: CVE-2026-4103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')