CVE-2024-6541
Received Received - Intake

Class Mediator MessageContext Property Validation Flaw

Vulnerability report for CVE-2024-6541, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wso2 class_mediator *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Class Mediator in WSO2 products does not properly validate or sanitize messageContext properties used for dynamic values. This flaw allows authenticated users to access or modify data across system invocations that should be isolated, potentially leading to unauthorized data exposure or system changes.

Impact Analysis

Authenticated users could access sensitive information belonging to other users or unintentionally modify system data. The impact depends on how messageContext properties are used in the affected WSO2 products.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, which may violate GDPR (data protection) or HIPAA (health data privacy) requirements. Non-compliance risks include legal penalties and reputational damage.

Mitigation Strategies

Immediately update or patch the WSO2 Class Mediator to ensure proper validation and sanitization of messageContext properties. Review and restrict access controls for authenticated users to prevent unauthorized data access or modification.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-6541. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart