CVE-2026-4249
CVE-2026-4249 is a high-severity vulnerability in Wso2 Api Control Plane with a CVSS 3.x base score of 8.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-707.
Key facts
- Severity: High (CVSS 3.x base score 8.6)
- EPSS exploit prediction: 0% (27th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-707
- Affected product: Wso2 Api Control Plane
- Published:
- Last modified:
Description
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.
Frequently asked questions
- What is CVE-2026-4249?
- The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.
- How severe is CVE-2026-4249?
- CVE-2026-4249 has a CVSS 3.x base score of 8.6, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-4249 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (27th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-4249?
- CVE-2026-4249 primarily affects Wso2 Api Control Plane. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-4249?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-4249 published?
- CVE-2026-4249 was published on 2026-07-06 and last updated on 2026-07-09.
References
Affected products (4)
- cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*
More vulnerabilities in Wso2 Api Control Plane
- CVE-2026-5430 — Critical (CVSS 10.0): The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or…
- CVE-2026-1728 — Critical (CVSS 9.8): Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access…
- CVE-2025-9312 — Critical (CVSS 9.8): A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST…
- CVE-2025-9152 — Critical (CVSS 9.8): An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and…
- CVE-2025-10611 — Critical (CVSS 9.8): Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks…
- CVE-2025-9804 — Critical (CVSS 9.6): An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in…
All CVEs affecting Wso2 Api Control Plane →
Other CWE-707 (Improper Neutralization) vulnerabilities
- CVE-2023-46689 — High (CVSS 8.8): Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to…
- CVE-2023-42773 — High (CVSS 8.8): Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to…
- CVE-2024-43572 — High (CVSS 7.8): Microsoft Management Console Remote Code Execution Vulnerability
- CVE-2019-10052 — High (CVSS 7.5): An issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to…
- CVE-2018-3918 — High (CVSS 7.5): An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version…
- CVE-2022-3973 — High (CVSS 7.3): A vulnerability classified as critical has been found in Pingkon HMS-PHP. Affected is an unknown function of the file…
Browse all CWE-707 (Improper Neutralization) vulnerabilities →