
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2053 is a Server-Side Request Forgery (SSRF) vulnerability in the WSO2 API Manager's message flow component that allows unauthenticated attackers to manipulate WS-Addressing headers and redirect server-initiated requests to arbitrary destinations. It affects WSO2 API Manager versions 3.1.0 (before 3.1.0.360), 3.2.0 (before 3.2.0.465), 3.2.1 (before 3.2.1.84), 4.0.0 (before 4.0.0.385), and 4.2.0 (before 4.2.0.189). The vulnerability was disclosed on June 26, 2026, with a patch available on the same date. It carries a CVSS v3.1 base score of 10.0 (Critical) per NVD, and 8.3 (High) per the GitHub Advisory Database and WSO2's own advisory (GitHub Advisory, WSO2 Advisory).
The root cause is insufficient input validation in the WSO2 API Manager's message flow component when processing WS-Addressing (WS-A) headers, classified as CWE-918 (Server-Side Request Forgery). WS-Addressing headers such as wsa:To or wsa:ReplyTo are used to specify message destinations in SOAP-based web services; because the API Manager does not validate or restrict user-supplied values in these headers, an attacker can craft a request that causes the server to initiate outbound connections to attacker-controlled or internal destinations. Exploitation requires no authentication, no user interaction, and is achievable remotely over the network with low attack complexity, making it highly automatable (GitHub Advisory, WSO2 Advisory).
Successful exploitation enables an unauthenticated remote attacker to control the destination of server-initiated requests from the WSO2 API Manager, effectively using the API Manager as a proxy to reach internal network resources and services that are otherwise inaccessible from external networks. This can lead to unauthorized access to internal APIs, databases, metadata services (e.g., cloud instance metadata endpoints), or other backend infrastructure, with high impacts to confidentiality, integrity, and availability per the NVD CVSS score. The changed scope indicator reflects that the impact extends beyond the vulnerable component itself to other internal systems (GitHub Advisory, WSO2 Advisory).
/services/, port 8243/8280). Confirm the version is within the affected range (3.1.0–4.2.0 before respective patch levels).wsa:To or wsa:ReplyTo header pointing to an internal target (e.g., http://169.254.169.254/latest/meta-data/ for cloud metadata, or an internal service IP).169.254.169.254), or unexpected external destinations; repeated SOAP requests to API Manager service endpoints from a single external IP.wsa:To or wsa:ReplyTo header values; server-side error logs indicating failed connection attempts to internal hosts not normally contacted by the API Manager.WSO2 has released patched versions addressing this vulnerability: 3.1.0.360, 3.2.0.465, 3.2.1.84, 4.0.0.385, and 4.2.0.189. Organizations should upgrade to the appropriate patched version as the primary remediation. As interim mitigations, implement network segmentation to restrict the WSO2 API Manager's ability to initiate outbound requests to only explicitly required internal services, and deploy perimeter-level filtering to block or validate WS-Addressing headers in incoming SOAP traffic. Monitoring and logging all server-initiated outbound requests from the API Manager is also recommended to detect exploitation attempts (WSO2 Advisory, GitHub Advisory).
The vulnerability received automated coverage across vulnerability tracking platforms including Vulners, CVEFeed, VulDB, and CIRCL shortly after disclosure on June 26, 2026. A Bluesky post from a CVE tracking account noted the advisory. No significant independent researcher commentary, vendor blog posts, or major media coverage has been identified beyond the standard vulnerability database entries as of the available data.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."