WSO2 API Manager and Identity Server Reflected XSS Enables Session Manipulation and Credential Theft (CVE-2026-2445)
Scope: WSO2 API Manager 4.2.0 to 4.6.0 and WSO2 Identity Server 6.0.0 and 7.1.0 (Multiple Sub-Versions, See Vendor Advisory)
Severity: High
A reflected cross-site scripting vulnerability in multiple WSO2 products, including API Manager and Identity Server, stems from insufficient output encoding of user-supplied URL parameters before they are rendered in HTTP responses, allowing an attacker to craft a malicious link that injects arbitrary JavaScript into the victim's browser session when clicked. Successful exploitation enables redirection to phishing sites, display of fake login forms to harvest administrator credentials, and retrieval of sensitive information from the active user session, with WSO2 noting that session cookie theft specifically is partially mitigated by the httpOnly flag though all other XSS-based attack vectors remain viable. WSO2 API Manager and Identity Server are deployed in several African government and enterprise API gateway environments including some on the continent with NITA-style mandates, making this advisory directly relevant. Organizations must apply the patch update levels specified in WSO2 Security Advisory WSO2-2025-4251 for their specific product version immediately via the WSO2 Update tool, and train users to identify and avoid suspicious links carrying unexpected URL parameters.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.