Refine your search

1 vulnerability found for WSO2 Carbon Event Publisher Core by WSO2

CVE-2026-0637 (GCVE-0-2026-0637)
Vulnerability from cvelistv5
Published
2026-08-06 07:33
Modified
2026-08-06 12:32
CWE
  • CWE-532 - Insertion of Sensitive Information into Log Files
Summary
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
Impacted products
Vendor Product Version
WSO2 WSO2 API Manager Version: 3.1.0   < 3.1.0.357
Version: 3.2.0   < 3.2.0.465
Version: 3.2.1   < 3.2.1.84
Version: 4.1.0   < 4.1.0.249
Version: 4.2.0   < 4.2.0.189
Version: 4.3.0   < 4.3.0.100
Version: 4.4.0   < 4.4.0.64
Version: 4.5.0   < 4.5.0.49
Version: 4.6.0   < 4.6.0.13
Create a notification for this product.
   WSO2 WSO2 Traffic Manager Version: 4.5.0   < 4.5.0.48
Version: 4.6.0   < 4.6.0.13
Create a notification for this product.
   WSO2 WSO2 API Control Plane Version: 4.5.0   < 4.5.0.50
Version: 4.6.0   < 4.6.0.14
Create a notification for this product.
   WSO2 WSO2 Universal Gateway Version: 4.5.0   < 4.5.0.49
Version: 4.6.0   < 4.6.0.13
Create a notification for this product.
   WSO2 WSO2 Identity Server Version: 5.10.0   < 5.10.0.386
Version: 5.11.0   < 5.11.0.433
Version: 6.0.0   < 6.0.0.260
Version: 6.1.0   < 6.1.0.261
Version: 7.0.0   < 7.0.0.139
Version: 7.1.0   < 7.1.0.47
Version: 7.2.0   < 7.2.0.8
Create a notification for this product.
   WSO2 WSO2 Identity Server as Key Manager Version: 5.10.0   < 5.10.0.377
Create a notification for this product.
   WSO2 WSO2 Open Banking IAM Version: 2.0.0   < 2.0.0.426
Create a notification for this product.
   WSO2 WSO2 Open Banking AM Version: 2.0.0   < 2.0.0.406
Create a notification for this product.
   WSO2 WSO2 Carbon Event Publisher Core Version: 5.2.24   < 5.2.24.11
Version: 5.2.26   < 5.2.26.24
Version: 5.2.27   < 5.2.27.7
Version: 5.2.41   < 5.2.41.8
Version: 5.2.45   < 5.2.45.2
Version: 5.2.50   < 5.2.50.3
Version: 5.2.57   < 5.2.57.12
Version: 5.2.58   < 5.2.58.3
Version: 5.2.61   < 5.2.61.4
Version: 5.2.64   < 5.2.64.1
Version: 5.3.5   < 5.3.5.10
Version: 5.3.11   < 5.3.11.7
Version: 5.3.15   < 5.3.15.6
Version: 5.3.20   < 5.3.20.3
Version: 5.3.27   < 5.3.27.1
Patch: x
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-0637",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-06T12:32:02.648926Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-06T12:32:09.382Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "WSO2 API Manager",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "3.1.0",
              "status": "unknown",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "3.1.0.357",
              "status": "affected",
              "version": "3.1.0",
              "versionType": "custom"
            },
            {
              "lessThan": "3.2.0.465",
              "status": "affected",
              "version": "3.2.0",
              "versionType": "custom"
            },
            {
              "lessThan": "3.2.1.84",
              "status": "affected",
              "version": "3.2.1",
              "versionType": "custom"
            },
            {
              "lessThan": "4.1.0.249",
              "status": "affected",
              "version": "4.1.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.2.0.189",
              "status": "affected",
              "version": "4.2.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.3.0.100",
              "status": "affected",
              "version": "4.3.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.4.0.64",
              "status": "affected",
              "version": "4.4.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.5.0.49",
              "status": "affected",
              "version": "4.5.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.6.0.13",
              "status": "affected",
              "version": "4.6.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "WSO2 Traffic Manager",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "4.5.0",
              "status": "unknown",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.5.0.48",
              "status": "affected",
              "version": "4.5.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.6.0.13",
              "status": "affected",
              "version": "4.6.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "WSO2 API Control Plane",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "4.5.0",
              "status": "unknown",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.5.0.50",
              "status": "affected",
              "version": "4.5.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.6.0.14",
              "status": "affected",
              "version": "4.6.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "WSO2 Universal Gateway",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "4.5.0",
              "status": "unknown",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.5.0.49",
              "status": "affected",
              "version": "4.5.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.6.0.13",
              "status": "affected",
              "version": "4.6.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "WSO2 Identity Server",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "5.10.0",
              "status": "unknown",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "5.10.0.386",
              "status": "affected",
              "version": "5.10.0",
              "versionType": "custom"
            },
            {
              "lessThan": "5.11.0.433",
              "status": "affected",
              "version": "5.11.0",
              "versionType": "custom"
            },
            {
              "lessThan": "6.0.0.260",
              "status": "affected",
              "version": "6.0.0",
              "versionType": "custom"
            },
            {
              "lessThan": "6.1.0.261",
              "status": "affected",
              "version": "6.1.0",
              "versionType": "custom"
            },
            {
              "lessThan": "7.0.0.139",
              "status": "affected",
              "version": "7.0.0",
              "versionType": "custom"
            },
            {
              "lessThan": "7.1.0.47",
              "status": "affected",
              "version": "7.1.0",
              "versionType": "custom"
            },
            {
              "lessThan": "7.2.0.8",
              "status": "affected",
              "version": "7.2.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "WSO2 Identity Server as Key Manager",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "5.10.0",
              "status": "unknown",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "5.10.0.377",
              "status": "affected",
              "version": "5.10.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "WSO2 Open Banking IAM",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "2.0.0",
              "status": "unknown",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "2.0.0.426",
              "status": "affected",
              "version": "2.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "WSO2 Open Banking AM",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "2.0.0",
              "status": "unknown",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "2.0.0.406",
              "status": "affected",
              "version": "2.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "packageName": "org.wso2.carbon.analytics-common:org.wso2.carbon.event.publisher.core",
          "product": "WSO2 Carbon Event Publisher Core",
          "vendor": "WSO2",
          "versions": [
            {
              "lessThan": "5.2.24.11",
              "status": "affected",
              "version": "5.2.24",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.26.24",
              "status": "affected",
              "version": "5.2.26",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.27.7",
              "status": "affected",
              "version": "5.2.27",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.41.8",
              "status": "affected",
              "version": "5.2.41",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.45.2",
              "status": "affected",
              "version": "5.2.45",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.50.3",
              "status": "affected",
              "version": "5.2.50",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.57.12",
              "status": "affected",
              "version": "5.2.57",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.58.3",
              "status": "affected",
              "version": "5.2.58",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.61.4",
              "status": "affected",
              "version": "5.2.61",
              "versionType": "custom"
            },
            {
              "lessThan": "5.2.64.1",
              "status": "affected",
              "version": "5.2.64",
              "versionType": "custom"
            },
            {
              "lessThan": "5.3.5.10",
              "status": "affected",
              "version": "5.3.5",
              "versionType": "custom"
            },
            {
              "lessThan": "5.3.11.7",
              "status": "affected",
              "version": "5.3.11",
              "versionType": "custom"
            },
            {
              "lessThan": "5.3.15.6",
              "status": "affected",
              "version": "5.3.15",
              "versionType": "custom"
            },
            {
              "lessThan": "5.3.20.3",
              "status": "affected",
              "version": "5.3.20",
              "versionType": "custom"
            },
            {
              "lessThan": "5.3.27.1",
              "status": "affected",
              "version": "5.3.27",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "x",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.\n\nA malicious actor with access to the \u0027wso2carbon\u0027 log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access."
            }
          ],
          "value": "When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.\n\nA malicious actor with access to the \u0027wso2carbon\u0027 log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-242",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-242 CAPEC-242: Logging Sensitive Data"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-532",
              "description": "CWE-532: Insertion of Sensitive Information into Log Files",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-06T07:33:20.334Z",
        "orgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
        "shortName": "WSO2"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cspan style=\"background-color: transparent;\"\u003eFollow the instructions given on \u003c/span\u003e\u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution\"\u003e\u003cspan style=\"background-color: transparent;\"\u003ehttps://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution\u003c/span\u003e\u003c/a\u003e \u003cbr\u003e"
            }
          ],
          "value": "Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution"
        }
      ],
      "source": {
        "advisory": "WSO2-2025-4897",
        "discovery": "INTERNAL"
      },
      "title": "Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products",
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
    "assignerShortName": "WSO2",
    "cveId": "CVE-2026-0637",
    "datePublished": "2026-08-06T07:33:20.334Z",
    "dateReserved": "2026-01-06T05:51:26.145Z",
    "dateUpdated": "2026-08-06T12:32:09.382Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}