Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-0637

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-532 Exposición de información a través de archivos de log
Fecha de publicación:
06/08/2026
Última modificación:
12/08/2026

Descripción

*** Pendiente de traducción *** When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values.<br /> <br /> A malicious actor with access to the &amp;#39;wso2carbon&amp;#39; log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* 4.5.0 (incluyendo) 4.5.0.50 (excluyendo)
cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* 4.6.0 (incluyendo) 4.6.0.14 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 3.1.0 (incluyendo) 3.1.0.357 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 3.2.0 (incluyendo) 3.2.0.465 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 3.2.1 (incluyendo) 3.2.1.84 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.1.0 (incluyendo) 4.1.0.249 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.2.0 (incluyendo) 4.2.0.189 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.3.0 (incluyendo) 4.3.0.100 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.4.0 (incluyendo) 4.4.0.64 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.5.0 (incluyendo) 4.5.0.49 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.6.0 (incluyendo) 4.6.0.13 (excluyendo)
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* 5.10.0 (incluyendo) 5.10.0.386 (excluyendo)
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* 5.11.0 (incluyendo) 5.11.0.433 (excluyendo)
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* 6.0.0 (incluyendo) 6.0.0.260 (excluyendo)
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* 6.1.0 (incluyendo) 6.1.0.261 (excluyendo)