CVE-2026-0637
Received Received - Intake

Information Disclosure in WSO2 Carbon via Misconfigured Logs

Vulnerability report for CVE-2026-0637, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
wso2 api_control_plane *
wso2 api_manager *
wso2 identity_server *
wso2 open_banking_am_iam *
wso2 traffic_manager *
wso2 universal_gateway *
wso2 wso2carbon *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability occurs when an Event Publisher output adapter is misconfigured with irrelevant properties. The system logs these properties without proper validation or sanitization, potentially exposing sensitive data like user credentials in the 'wso2carbon' log files.

Detection Guidance

Check WSO2 log files, specifically the wso2carbon logs, for entries containing sensitive information like credentials or confidential data. Look for warn logs from Event Publisher output adapters with irrelevant properties.

Impact Analysis

A malicious actor with access to the log files could retrieve sensitive information such as credentials or confidential data, leading to unauthorized access or further exploitation of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection standards like GDPR and HIPAA, which mandate strict controls over personal and health information.

Mitigation Strategies

Apply public fixes or update to the latest unaffected versions of affected WSO2 products. For community users, apply the fix from the GitHub pull request. Support subscribers should update to specified versions as per the advisory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0637. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart