CVE-2026-2053Wso2 · Api_manager
Vulnerability data via NVD (ingested)
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-2053product:"Wso2 Api Manager"http.html:"Api Manager"More intel sources (5)
vuln:CVE-2026-2053vulnerabilities.cve_id: CVE-2026-2053CVE-2026-2053CVE-2026-2053"CVE-2026-2053" exploit -site:nvd.nist.gov