CVE-2026-0637 PUBLISHED

Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products

Assigner: WSO2
Reserved: 06.01.2026 Published: 06.08.2026 Updated: 06.08.2026

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.

A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 4.4

Product Status

Vendor WSO2
Product WSO2 API Manager
Versions Default: unaffected
  • unknown from 0 to 3.1.0 (excl.)
  • affected from 3.1.0 to 3.1.0.357 (excl.)
  • affected from 3.2.0 to 3.2.0.465 (excl.)
  • affected from 3.2.1 to 3.2.1.84 (excl.)
  • affected from 4.1.0 to 4.1.0.249 (excl.)
  • affected from 4.2.0 to 4.2.0.189 (excl.)
  • affected from 4.3.0 to 4.3.0.100 (excl.)
  • affected from 4.4.0 to 4.4.0.64 (excl.)
  • affected from 4.5.0 to 4.5.0.49 (excl.)
  • affected from 4.6.0 to 4.6.0.13 (excl.)
Vendor WSO2
Product WSO2 Traffic Manager
Versions Default: unaffected
  • unknown from 0 to 4.5.0 (excl.)
  • affected from 4.5.0 to 4.5.0.48 (excl.)
  • affected from 4.6.0 to 4.6.0.13 (excl.)
Vendor WSO2
Product WSO2 API Control Plane
Versions Default: unaffected
  • unknown from 0 to 4.5.0 (excl.)
  • affected from 4.5.0 to 4.5.0.50 (excl.)
  • affected from 4.6.0 to 4.6.0.14 (excl.)
Vendor WSO2
Product WSO2 Universal Gateway
Versions Default: unaffected
  • unknown from 0 to 4.5.0 (excl.)
  • affected from 4.5.0 to 4.5.0.49 (excl.)
  • affected from 4.6.0 to 4.6.0.13 (excl.)
Vendor WSO2
Product WSO2 Identity Server
Versions Default: unaffected
  • unknown from 0 to 5.10.0 (excl.)
  • affected from 5.10.0 to 5.10.0.386 (excl.)
  • affected from 5.11.0 to 5.11.0.433 (excl.)
  • affected from 6.0.0 to 6.0.0.260 (excl.)
  • affected from 6.1.0 to 6.1.0.261 (excl.)
  • affected from 7.0.0 to 7.0.0.139 (excl.)
  • affected from 7.1.0 to 7.1.0.47 (excl.)
  • affected from 7.2.0 to 7.2.0.8 (excl.)
Vendor WSO2
Product WSO2 Identity Server as Key Manager
Versions Default: unaffected
  • unknown from 0 to 5.10.0 (excl.)
  • affected from 5.10.0 to 5.10.0.377 (excl.)
Vendor WSO2
Product WSO2 Open Banking IAM
Versions Default: unaffected
  • unknown from 0 to 2.0.0 (excl.)
  • affected from 2.0.0 to 2.0.0.426 (excl.)
Vendor WSO2
Product WSO2 Open Banking AM
Versions Default: unaffected
  • unknown from 0 to 2.0.0 (excl.)
  • affected from 2.0.0 to 2.0.0.406 (excl.)
Vendor WSO2
Product WSO2 Carbon Event Publisher Core
Versions Default: unknown
  • affected from 5.2.24 to 5.2.24.11 (excl.)
  • affected from 5.2.26 to 5.2.26.24 (excl.)
  • affected from 5.2.27 to 5.2.27.7 (excl.)
  • affected from 5.2.41 to 5.2.41.8 (excl.)
  • affected from 5.2.45 to 5.2.45.2 (excl.)
  • affected from 5.2.50 to 5.2.50.3 (excl.)
  • affected from 5.2.57 to 5.2.57.12 (excl.)
  • affected from 5.2.58 to 5.2.58.3 (excl.)
  • affected from 5.2.61 to 5.2.61.4 (excl.)
  • affected from 5.2.64 to 5.2.64.1 (excl.)
  • affected from 5.3.5 to 5.3.5.10 (excl.)
  • affected from 5.3.11 to 5.3.11.7 (excl.)
  • affected from 5.3.15 to 5.3.15.6 (excl.)
  • affected from 5.3.20 to 5.3.20.3 (excl.)
  • affected from 5.3.27 to 5.3.27.1 (excl.)
  • unaffected from x to * (incl.)

Solutions

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4897/#solution

References

Problem Types

  • CWE-532: Insertion of Sensitive Information into Log Files CWE

Impacts

  • CAPEC-242 CAPEC-242: Logging Sensitive Data