CVE-2026-3416

HIGH CVSS 3.1: 7.5 EPSS 0.26%
Updated Sep 15, 2026
Wso2
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions 4.1.0 — 4.5.0.53
Fixed In 4.5.0.53
Type CWE-330
Vendor Wso2
Public PoC No

The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification.

Successful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 6

Configuration From (including) Up to (excluding)
Wso2 Api_Control_Plane
cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*
4.5.0 4.5.0.53
Wso2 Api_Manager
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
4.1.0 4.1.0.253
Wso2 Api_Manager
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
4.2.0 4.2.0.193
Wso2 Api_Manager
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
4.3.0 4.3.0.104
Wso2 Api_Manager
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
4.4.0 4.4.0.68
Wso2 Api_Manager
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
4.5.0 4.5.0.52