CVE-2026-0637
Analyzed Analyzed - Analysis Complete

Information Disclosure in WSO2 Carbon via Misconfigured Logs

Vulnerability report for CVE-2026-0637, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-12

Assigner: WSO2 LLC

Description

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-12
Generated
2026-08-17
AI Q&A
2026-08-06
EPSS Evaluated
2026-08-16
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
wso2 api_manager From 3.2.0 (inc) to 3.2.0.465 (exc)
wso2 api_manager From 3.2.1 (inc) to 3.2.1.84 (exc)
wso2 api_manager From 4.2.0 (inc) to 4.2.0.189 (exc)
wso2 api_control_plane From 4.5.0 (inc) to 4.5.0.50 (exc)
wso2 api_control_plane From 4.6.0 (inc) to 4.6.0.14 (exc)
wso2 api_manager From 3.1.0 (inc) to 3.1.0.357 (exc)
wso2 api_manager From 4.1.0 (inc) to 4.1.0.249 (exc)
wso2 api_manager From 4.3.0 (inc) to 4.3.0.100 (exc)
wso2 api_manager From 4.4.0 (inc) to 4.4.0.64 (exc)
wso2 api_manager From 4.5.0 (inc) to 4.5.0.49 (exc)
wso2 api_manager From 4.6.0 (inc) to 4.6.0.13 (exc)
wso2 identity_server From 5.10.0 (inc) to 5.10.0.386 (exc)
wso2 identity_server From 5.11.0 (inc) to 5.11.0.433 (exc)
wso2 identity_server From 6.0.0 (inc) to 6.0.0.260 (exc)
wso2 identity_server From 6.1.0 (inc) to 6.1.0.261 (exc)
wso2 identity_server_as_key_manager From 5.10.0 (inc) to 5.10.0.377 (exc)
wso2 open_banking_am From 2.0.0 (inc) to 2.0.0.406 (exc)
wso2 open_banking_iam From 2.0.0 (inc) to 2.0.0.426 (exc)
wso2 traffic_manager From 4.5.0 (inc) to 4.5.0.48 (exc)
wso2 traffic_manager From 4.6.0 (inc) to 4.6.0.13 (exc)
wso2 universal_gateway From 4.5.0 (inc) to 4.5.0.49 (exc)
wso2 universal_gateway From 4.6.0 (inc) to 4.6.0.13 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability occurs when an Event Publisher output adapter is misconfigured with irrelevant properties. The system logs these properties without proper validation or sanitization, potentially exposing sensitive data like user credentials in the 'wso2carbon' log files.

Detection Guidance

Check WSO2 log files, specifically the wso2carbon logs, for entries containing sensitive information like credentials or confidential data. Look for warn logs from Event Publisher output adapters with irrelevant properties.

Impact Analysis

A malicious actor with access to the log files could retrieve sensitive information such as credentials or confidential data, leading to unauthorized access or further exploitation of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection standards like GDPR and HIPAA, which mandate strict controls over personal and health information.

Mitigation Strategies

Apply public fixes or update to the latest unaffected versions of affected WSO2 products. For community users, apply the fix from the GitHub pull request. Support subscribers should update to specified versions as per the advisory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0637. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart