CVE-2026-2053Patch(wso2 / api_manager)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wso2 api_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • api_manager

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-06-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
api_manager

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 106-2606-27
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • SecAlerts@SecAlertsCo
    Patch

    🔗 WSO2 API Manager has a critical unauthenticated SSRF — CVE-2026-2053. Attackers can abuse WS-Addressing headers in the message flow with no auth required. Patch now. https://secalerts.co/vulnerability/CVE-2026-2053?utm_campaign=x #WSO2 #AppSec https://t.co/ymPuf2gyZB

    Post summary

    The tweet alerts about WSO2 API Manager's CVE-2026-2053, an unauthenticated SSRF vulnerability, and urges users to apply the available patch.

    0000094
    845 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - WSO2 API Manager WS-Addressing SSRF (CVE-2026-2053) The WSO2 API Manager's message flow component does not sufficiently validate user-controlled input within WS-Addressing headers. This allows an unauthenticated attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation enables unauthorized access to internal network resources or services that would normally be inaccessible from external networks (SSRF). 👉Affected: WSO2 API Manager (versions affected prior to the latest security update) Action: Apply the latest security patches from WSO2.

    Post summary

    The tweet announces CVE-2026-2053 for WSO2 API Manager, describes an SSRF vulnerability, and urges users to apply the latest vendor patches.

    0000065
    231 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2api_manager---

Explore more