---
id: CVE-2026-4103
title: >-
  Insufficient HTML sanitization in the Publisher Portal and Developer Portal
  allows untrusted user input to be rendered without proper encoding or
  neutralization
summary: >-
  Insufficient HTML sanitization in the Publisher Portal and Developer Portal
  allows untrusted user input to be rendered without proper encoding or
  neutralization. This enables the injection and execution of malicious
  JavaScript when affec…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: WSO2
product: WSO2 API Control Plane
affected:
  - api_control_plane >= 4.5.0 < 4.5.0.55
  - api_control_plane >= 4.6.0 < 4.6.0.19
  - api_manager >= 3.2.0 < 3.2.0.470
  - api_manager >= 3.2.1 < 3.2.1.89
  - api_manager >= 4.1.0 < 4.1.0.254
  - api_manager >= 4.2.0 < 4.2.0.194
  - api_manager >= 4.3.0 < 4.3.0.105
  - api_manager >= 4.4.0 < 4.4.0.69
  - api_manager >= 4.5.0 < 4.5.0.54
  - api_manager >= 4.6.0 < 4.6.0.18
published: '2026-09-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:13:15.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4103'
references:
  - url: >-
      https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-4844/
    label: ed10eef1-636d-4fbe-9993-6890dfa878f8
tags:
  - nvd
  - cve.org
epss: 0.0018
epssPercentile: 0.07842
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:12:26.565275Z'
ingestedAt: '2026-09-14T17:11:16.563Z'
---

## Overview

Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API documents are viewed.

Successful exploitation may result in the execution of malicious scripts within the user's browser context when viewing API documentation. Users with permissions to access the API documentation through these portals may be impacted, potentially allowing attackers to perform actions on behalf of the user, depending on their session privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
