Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
4.7
CVE-2026-3096PATCHED
wso2 · wso2 api control plane

Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft

Description

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.

Affected Products

VendorProductVersions
wso2wso2 api control plane4.5.0, 4.6.0, 3.2.0, 3.2.1, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.5.0, 4.6.0

References

  • https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5164/(vendor-advisory)

Related News (1 articles)

Tier C
VulDB17d ago
CVE-2026-3096 | WSO2 API Control Plane/API Manager input validation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.14.7 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.5.0.544.6.0.183.2.0.4683.2.1.874.1.0.2524.2.0.1924.3.0.1034.4.0.674.5.0.524.6.0.16
CWECWE-20, CWE-603
PublishedSep 10, 2026
Trending Score3
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Trending: 55
MEDIUMCVE-2025-5802
Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery
Trending: 7
HIGHCVE-2026-19515
OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution
Trending: 7
LOWCVE-2025-13166
Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery
Trending: 4
MEDIUMCVE-2026-4103
Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 10, 2026
Discovered by ZDM
Sep 10, 2026
Patch Available
Sep 11, 2026