CVE-2026-3416Medium· 5.9▾ SunlitThe API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a s…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification.
Successful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise.
api_control_plane >= 4.5.0, < 4.5.0.53api_manager >= 4.1.0, < 4.1.0.253api_manager >= 4.2.0, < 4.2.0.193api_manager >= 4.3.0, < 4.3.0.104api_manager >= 4.4.0, < 4.4.0.68api_manager >= 4.5.0, < 4.5.0.52Upgrade past the affected range:
api_control_plane 4.5.0.53api_manager 4.5.0.52Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12737High· 8.4The administrative operations within the Carbon Console do not adequately validate specific user-supplied input
CVE-2024-6832Medium· 5.9The account locking mechanism fails to trigger when secondary user stores are inaccessible
CVE-2024-10302Medium· 4.0The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input
CVE-2021-20322High· 7.4A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports
CVE-2026-19515High· 7.0The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources
CVE-2025-5802Medium· 5.3The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence