CVE-2026-4103 PUBLISHED

Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution

Assigner: WSO2
Reserved: 13.03.2026 Published: 14.09.2026 Updated: 14.09.2026

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API documents are viewed.

Successful exploitation may result in the execution of malicious scripts within the user's browser context when viewing API documentation. Users with permissions to access the API documentation through these portals may be impacted, potentially allowing attackers to perform actions on behalf of the user, depending on their session privileges.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS Score: 6.4

Product Status

Vendor WSO2
Product WSO2 API Control Plane
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.55 (excl.)
  • affected from 4.6.0 to 4.6.0.19 (excl.)
Vendor WSO2
Product WSO2 API Manager
Versions Default: unaffected
  • unknown from 0 to 3.2.0 (excl.)
  • affected from 3.2.0 to 3.2.0.470 (excl.)
  • affected from 3.2.1 to 3.2.1.89 (excl.)
  • affected from 4.1.0 to 4.1.0.254 (excl.)
  • affected from 4.2.0 to 4.2.0.194 (excl.)
  • affected from 4.3.0 to 4.3.0.105 (excl.)
  • affected from 4.4.0 to 4.4.0.69 (excl.)
  • affected from 4.5.0 to 4.5.0.54 (excl.)
  • affected from 4.6.0 to 4.6.0.18 (excl.)

Solutions

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-4844/#solution

Credits

  • San Gil from Security Office finder

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE

Impacts

  • CAPEC-22 CAPEC-22: Cross-site Scripting