Answer in brief
CVE-2025-13394 records a Medium severity (CVSS 5.4) vulnerability in Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon Command Mediator UI (generic), WSO2/WSO2 Carbon Component Andes Event UI (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon Command Mediator UI (generic), WSO2/WSO2 Carbon Component Andes Event UI (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.39 || >=4.6.0 <4.6.0.3 | 4.5.0.39, 4.6.0.3 |
| WSO2/WSO2 API Managergeneric | >=3.1.0 <3.1.0.352 || >=3.2.0 <3.2.0.456 || >=3.2.1 <3.2.1.75 || >=4.0.0 <4.0.0.376 || >=4.1.0 <4.1.0.239 || >=4.2.0 <4.2.0.179 || >=4.3.0 <4.3.0.91 || >=4.4.0 <4.4.0.55 || >=4.5.0 <4.5.0.38 || >=4.6.0 <4.6.0.3 | 3.1.0.352, 3.2.0.456, 3.2.1.75, 4.0.0.376, 4.1.0.239, 4.2.0.179, 4.3.0.91, 4.4.0.55, 4.5.0.38, 4.6.0.3 |
| WSO2/WSO2 Carbon Command Mediator UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Component Andes Event UIgeneric | >=3.3.12 <3.3.12.3 | 3.3.12.3 |
| WSO2/WSO2 Carbon Component Andes UI1generic | >=3.3.12 <3.3.12.3 | 3.3.12.3 |
| WSO2/WSO2 Carbon Email Verification UIgeneric | >=4.7.19 <4.7.19.14 | 4.7.19.14 |
| WSO2/WSO2 Carbon Endpoint Editor UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Eventing UIgeneric | >=4.7.19 <4.7.19.13 | 4.7.19.13 |
| WSO2/WSO2 Carbon Event Simulator UIgeneric | >=2.2.11 <2.2.11.1 || >=2.2.14 <2.2.14.11 || >=2.2.14 <2.2.14.12 || >=2.2.17 <2.2.17.5 || >=2.3.1 <2.3.1.4 || >=2.3.5 <2.3.5.6 | 2.2.11.1, 2.2.14.11, 2.2.14.12, 2.2.17.5, 2.3.1.4, 2.3.5.6 |
| WSO2/WSO2 Carbon Execution Manager UIgeneric | >=5.2.24 <5.2.24.10 || >=5.2.26 <5.2.26.22 || >=5.2.34 <5.2.34.12 || >=5.2.41 <5.2.41.7 || >=5.2.57 <5.2.57.10 || >=5.3.5 <5.3.5.9 | 5.2.24.10, 5.2.26.22, 5.2.34.12, 5.2.41.7, 5.2.57.10, 5.3.5.9 |
| WSO2/WSO2 Carbon Governancegeneric | >=4.8.37 <4.8.37.4 | 4.8.37.4 |
| WSO2/WSO2 Carbon Governance Custom Lifecycle Checklist UIgeneric | >=4.8.14 <4.8.14.4 || >=4.8.19 <4.8.19.8 || >=4.8.21 <4.8.21.10 || >=4.8.28 <4.8.28.4 || >=4.8.30 <4.8.30.6 || >=4.8.32 <4.8.32.4 | 4.8.14.4, 4.8.19.8, 4.8.21.10, 4.8.28.4, 4.8.30.6, 4.8.32.4 |
| WSO2/WSO2 Carbon Governance Generic Artifact User Interfacegeneric | >=4.8.14 <4.8.14.4 || >=4.8.19 <4.8.19.8 || >=4.8.21 <4.8.21.10 || >=4.8.28 <4.8.28.4 || >=4.8.30 <4.8.30.6 || >=4.8.32 <4.8.32.4 || >=4.8.33 <4.8.33.4 || >=4.8.34 <4.8.34.5 || >=4.8.37 <4.8.37.4 | 4.8.14.4, 4.8.19.8, 4.8.21.10, 4.8.28.4, 4.8.30.6, 4.8.32.4, 4.8.33.4, 4.8.34.5, 4.8.37.4 |
| WSO2/WSO2 Carbon Governance Life Cycles User Interfacegeneric | >=4.8.14 <4.8.14.4 || >=4.8.19 <4.8.19.8 || >=4.8.21 <4.8.21.10 || >=4.8.28 <4.8.28.4 || >=4.8.30 <4.8.30.6 || >=4.8.32 <4.8.32.4 | 4.8.14.4, 4.8.19.8, 4.8.21.10, 4.8.28.4, 4.8.30.6, 4.8.32.4 |
| WSO2/WSO2 Carbon Governance WSDL Tool UIgeneric | >=4.8.14 <4.8.14.4 || >=4.8.19 <4.8.19.8 || >=4.8.21 <4.8.21.10 || >=4.8.28 <4.8.28.4 || >=4.8.30 <4.8.30.6 || >=4.8.32 <4.8.32.4 || >=4.8.33 <4.8.33.4 || >=4.8.34 <4.8.34.5 || >=4.8.37 <4.8.37.4 | 4.8.14.4, 4.8.19.8, 4.8.21.10, 4.8.28.4, 4.8.30.6, 4.8.32.4, 4.8.33.4, 4.8.34.5, 4.8.37.4 |
| WSO2/WSO2 Carbon HL7 Business Messaging Store UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon HumanTask UIgeneric | >=4.5.27 <4.5.27.10 | 4.5.27.10 |
| WSO2/WSO2 Carbon Identity Entitlement UIgeneric | >=5.17.5 <5.17.5.331 || >=5.18.187 <5.18.187.329 || >=5.23.8 <5.23.8.210 || >=5.25.92 <5.25.92.166 || >=7.0.78 <7.0.78.157 | 5.17.5.331, 5.18.187.329, 5.23.8.210, 5.25.92.166, 7.0.78.157 |
| WSO2/WSO2 Carbon Identity Management UI1generic | >=5.17.5 <5.17.5.330 || >=5.17.5 <5.17.5.331 || >=5.17.118 <5.17.118.22 || >=5.18.187 <5.18.187.328 || >=5.18.187 <5.18.187.329 || >=5.18.248 <5.18.248.31 || >=5.23.8 <5.23.8.210 || >=5.24.8 <5.24.8.26 || >=5.25.92 <5.25.92.166 || >=5.25.705 <5.25.705.21 || >=5.25.713 <5.25.713.10 || >=5.25.724 <5.25.724.5 || >=5.25.736 <5.25.736.1 || >=7.0.78 <7.0.78.157 || >=7.8.23 <7.8.23.67 || >=7.8.586 <7.8.586.7 | 5.17.5.330, 5.17.5.331, 5.17.118.22, 5.18.187.328, 5.18.187.329, 5.18.248.31, 5.23.8.210, 5.24.8.26, 5.25.92.166, 5.25.705.21, 5.25.713.10, 5.25.724.5, 5.25.736.1, 7.0.78.157, 7.8.23.67, 7.8.586.7 |
| WSO2/WSO2 Carbon Identity User Store Configuration UIgeneric | >=5.14.127 <5.14.127.13 || >=5.17.5 <5.17.5.330 || >=5.17.5 <5.17.5.331 || >=5.17.118 <5.17.118.22 || >=5.18.187 <5.18.187.328 || >=5.18.187 <5.18.187.329 || >=5.18.248 <5.18.248.31 || >=5.23.8 <5.23.8.210 || >=5.24.8 <5.24.8.26 || >=5.25.92 <5.25.92.166 || >=5.25.705 <5.25.705.21 || >=5.25.713 <5.25.713.10 || >=5.25.724 <5.25.724.5 || >=5.25.736 <5.25.736.1 || >=7.0.78 <7.0.78.157 || >=7.8.23 <7.8.23.67 || >=7.8.586 <7.8.586.7 | 5.14.127.13, 5.17.5.330, 5.17.5.331, 5.17.118.22, 5.18.187.328, 5.18.187.329, 5.18.248.31, 5.23.8.210, 5.24.8.26, 5.25.92.166, 5.25.705.21, 5.25.713.10, 5.25.724.5, 5.25.736.1, 7.0.78.157, 7.8.23.67, 7.8.586.7 |
| WSO2/WSO2 Carbon Logging UIgeneric | >=4.7.19 <4.7.19.13 || >=4.7.24 <4.7.24.5 || >=4.7.32 <4.7.32.10 || >=4.7.52 <4.7.52.5 | 4.7.19.13, 4.7.24.5, 4.7.32.10, 4.7.52.5 |
| WSO2/WSO2 Carbon New Data Sources UIgeneric | >=4.7.19 <4.7.19.13 || >=4.7.24 <4.7.24.5 || >=4.7.32 <4.7.32.10 || >=4.7.35 <4.7.35.13 || >=4.7.49 <4.7.49.7 || >=4.7.52 <4.7.52.5 || >=4.9.2 <4.9.2.8 || >=4.9.11 <4.9.11.2 || >=4.9.18 <4.9.18.1 | 4.7.19.13, 4.7.24.5, 4.7.32.10, 4.7.35.13, 4.7.49.7, 4.7.52.5, 4.9.2.8, 4.9.11.2, 4.9.18.1 |
| WSO2/WSO2 Carbon Publish Event Mediator Configuration UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Registry Indexinggeneric | >=4.7 <4.7.24 | 4.7.24 |
| WSO2/WSO2 Carbon Registry Info UI2generic | >=4.7.32 <4.7.32.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.13 <4.8.13.9 || >=4.8.32 <4.8.32.4 || >=4.8.36 <4.8.36.2 || >=4.8.43 <4.8.43.2 || >=4.8.50 <4.8.50.1 | 4.7.32.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.13.9, 4.8.32.4, 4.8.36.2, 4.8.43.2, 4.8.50.1 |
| WSO2/WSO2 Carbon Registry Profiles UIgeneric | >=4.7.32 <4.7.32.18 || >=4.7.33 <4.7.33.16 || >=4.8.9 <4.8.9.16 || >=4.8.12 <4.8.12.8 || >=4.8.24 <4.8.24.6 || >=4.8.43 <4.8.43.4 || >=4.8.50 <4.8.50.3 | 4.7.32.18, 4.7.33.16, 4.8.9.16, 4.8.12.8, 4.8.24.6, 4.8.43.4, 4.8.50.3 |
| WSO2/WSO2 Carbon Registry Properties UIgeneric | >=4.7.24 <4.7.24.11 || >=4.7.32 <4.7.32.16 || >=4.7.32 <4.7.32.18 || >=4.7.33 <4.7.33.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.9 <4.8.9.16 || >=4.8.12 <4.8.12.8 || >=4.8.13 <4.8.13.9 || >=4.8.24 <4.8.24.6 || >=4.8.32 <4.8.32.4 || >=4.8.36 <4.8.36.2 || >=4.8.43 <4.8.43.2 || >=4.8.43 <4.8.43.4 || >=4.8.50 <4.8.50.1 || >=4.8.50 <4.8.50.3 | 4.7.24.11, 4.7.32.16, 4.7.32.18, 4.7.33.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.9.16, 4.8.12.8, 4.8.13.9, 4.8.24.6, 4.8.32.4, 4.8.36.2, 4.8.43.2, 4.8.43.4, 4.8.50.1, 4.8.50.3 |
| WSO2/WSO2 Carbon Registry Relations UIgeneric | >=4.7.24 <4.7.24.11 || >=4.7.32 <4.7.32.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.13 <4.8.13.9 || >=4.8.32 <4.8.32.4 || >=4.8.36 <4.8.36.2 || >=4.8.43 <4.8.43.2 || >=4.8.50 <4.8.50.1 | 4.7.24.11, 4.7.32.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.13.9, 4.8.32.4, 4.8.36.2, 4.8.43.2, 4.8.50.1 |
| WSO2/WSO2 Carbon Registry Resources UIgeneric | >=4.7.24 <4.7.24.11 || >=4.7.32 <4.7.32.16 || >=4.7.32 <4.7.32.18 || >=4.7.33 <4.7.33.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.9 <4.8.9.16 || >=4.8.12 <4.8.12.8 || >=4.8.13 <4.8.13.9 || >=4.8.24 <4.8.24.6 || >=4.8.32 <4.8.32.4 || >=4.8.36 <4.8.36.2 || >=4.8.43 <4.8.43.2 || >=4.8.43 <4.8.43.4 || >=4.8.50 <4.8.50.1 || >=4.8.50 <4.8.50.3 | 4.7.24.11, 4.7.32.16, 4.7.32.18, 4.7.33.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.9.16, 4.8.12.8, 4.8.13.9, 4.8.24.6, 4.8.32.4, 4.8.36.2, 4.8.43.2, 4.8.43.4, 4.8.50.1, 4.8.50.3 |
| WSO2/WSO2 Carbon Registry Search UIgeneric | >=4.7.24 <4.7.24.11 || >=4.7.32 <4.7.32.16 || >=4.7.32 <4.7.32.18 || >=4.7.33 <4.7.33.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.9 <4.8.9.16 || >=4.8.12 <4.8.12.8 || >=4.8.13 <4.8.13.9 || >=4.8.24 <4.8.24.6 | 4.7.24.11, 4.7.32.16, 4.7.32.18, 4.7.33.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.9.16, 4.8.12.8, 4.8.13.9, 4.8.24.6 |
| WSO2/WSO2 Carbon Rest API Admin UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Rule Mediator UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Security UIgeneric | >=5.14 <5.14.127 | 5.14.127 |
| WSO2/WSO2 Carbon Sequence Editor UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Tasks Coregeneric | >=4.7.19 <4.7.19.13 | 4.7.19.13 |
| WSO2/WSO2 Carbon Task UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Template Editor UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Throttle Mediator UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Enterprise Integratorgeneric | >=6.6.0 <6.6.0.227 | 6.6.0.227 |
| WSO2/WSO2 Identity Servergeneric | >=5.10.0 <5.10.0.381 || >=5.11.0 <5.11.0.428 || >=6.0.0 <6.0.0.255 || >=6.1.0 <6.1.0.256 || >=7.0.0 <7.0.0.133 || >=7.1.0 <7.1.0.41 || >=7.2.0 <7.2.0.3 | 5.10.0.381, 5.11.0.428, 6.0.0.255, 6.1.0.256, 7.0.0.133, 7.1.0.41, 7.2.0.3 |
| WSO2/WSO2 Identity Server as Key Managergeneric | >=5.10.0 <5.10.0.372 | 5.10.0.372 |
| WSO2/WSO2 Open Banking AMgeneric | >=2.0.0 <2.0.0.401 | 2.0.0.401 |
| WSO2/WSO2 Open Banking IAMgeneric | >=2.0.0 <2.0.0.421 | 2.0.0.421 |
| WSO2/WSO2 Stratos SSO Redirector UI Componentgeneric | >=4.8.1 <4.8.1.6 | 4.8.1.6 |
| WSO2/WSO2 Stratos User Interface For Tenant CRUD Operationsgeneric | >=4.8.1 <4.8.1.6 || >=4.8.7 <4.8.7.3 || >=4.9.8 <4.9.8.7 || >=4.9.10 <4.9.10.7 || >=4.9.10 <4.9.10.8 || >=4.9.20 <4.9.20.5 || >=4.9.27 <4.9.27.1 || >=4.9.31 <4.9.31.1 || >=4.9.34 <4.9.34.1 || >=4.9.42 <4.9.42.1 || >=4.11.0 <4.11.0.7 || >=4.11.19 <4.11.19.4 || >=4.11.34 <4.11.34.3 || >=4.11.45 <4.11.45.1 | 4.8.1.6, 4.8.7.3, 4.9.8.7, 4.9.10.7, 4.9.10.8, 4.9.20.5, 4.9.27.1, 4.9.31.1, 4.9.34.1, 4.9.42.1, 4.11.0.7, 4.11.19.4, 4.11.34.3, 4.11.45.1 |
| WSO2/WSO2 Traffic Managergeneric | >=4.5.0 <4.5.0.37 || >=4.6.0 <4.6.0.3 | 4.5.0.37, 4.6.0.3 |
| WSO2/WSO2 Universal Gatewaygeneric | >=4.5.0 <4.5.0.37 || >=4.6.0 <4.6.0.3 | 4.5.0.37, 4.6.0.3 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions. An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-13394 records a Medium severity (CVSS 5.4) vulnerability in Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon Command Mediator UI (generic), WSO2/WSO2 Carbon Component Andes Event UI (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon Command Mediator UI (generic), WSO2/WSO2 Carbon Component Andes Event UI (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.39 || >=4.6.0 <4.6.0.3 | 4.5.0.39, 4.6.0.3 |
| WSO2/WSO2 API Managergeneric | >=3.1.0 <3.1.0.352 || >=3.2.0 <3.2.0.456 || >=3.2.1 <3.2.1.75 || >=4.0.0 <4.0.0.376 || >=4.1.0 <4.1.0.239 || >=4.2.0 <4.2.0.179 || >=4.3.0 <4.3.0.91 || >=4.4.0 <4.4.0.55 || >=4.5.0 <4.5.0.38 || >=4.6.0 <4.6.0.3 | 3.1.0.352, 3.2.0.456, 3.2.1.75, 4.0.0.376, 4.1.0.239, 4.2.0.179, 4.3.0.91, 4.4.0.55, 4.5.0.38, 4.6.0.3 |
| WSO2/WSO2 Carbon Command Mediator UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Component Andes Event UIgeneric | >=3.3.12 <3.3.12.3 | 3.3.12.3 |
| WSO2/WSO2 Carbon Component Andes UI1generic | >=3.3.12 <3.3.12.3 | 3.3.12.3 |
| WSO2/WSO2 Carbon Email Verification UIgeneric | >=4.7.19 <4.7.19.14 | 4.7.19.14 |
| WSO2/WSO2 Carbon Endpoint Editor UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Eventing UIgeneric | >=4.7.19 <4.7.19.13 | 4.7.19.13 |
| WSO2/WSO2 Carbon Event Simulator UIgeneric | >=2.2.11 <2.2.11.1 || >=2.2.14 <2.2.14.11 || >=2.2.14 <2.2.14.12 || >=2.2.17 <2.2.17.5 || >=2.3.1 <2.3.1.4 || >=2.3.5 <2.3.5.6 | 2.2.11.1, 2.2.14.11, 2.2.14.12, 2.2.17.5, 2.3.1.4, 2.3.5.6 |
| WSO2/WSO2 Carbon Execution Manager UIgeneric | >=5.2.24 <5.2.24.10 || >=5.2.26 <5.2.26.22 || >=5.2.34 <5.2.34.12 || >=5.2.41 <5.2.41.7 || >=5.2.57 <5.2.57.10 || >=5.3.5 <5.3.5.9 | 5.2.24.10, 5.2.26.22, 5.2.34.12, 5.2.41.7, 5.2.57.10, 5.3.5.9 |
| WSO2/WSO2 Carbon Governancegeneric | >=4.8.37 <4.8.37.4 | 4.8.37.4 |
| WSO2/WSO2 Carbon Governance Custom Lifecycle Checklist UIgeneric | >=4.8.14 <4.8.14.4 || >=4.8.19 <4.8.19.8 || >=4.8.21 <4.8.21.10 || >=4.8.28 <4.8.28.4 || >=4.8.30 <4.8.30.6 || >=4.8.32 <4.8.32.4 | 4.8.14.4, 4.8.19.8, 4.8.21.10, 4.8.28.4, 4.8.30.6, 4.8.32.4 |
| WSO2/WSO2 Carbon Governance Generic Artifact User Interfacegeneric | >=4.8.14 <4.8.14.4 || >=4.8.19 <4.8.19.8 || >=4.8.21 <4.8.21.10 || >=4.8.28 <4.8.28.4 || >=4.8.30 <4.8.30.6 || >=4.8.32 <4.8.32.4 || >=4.8.33 <4.8.33.4 || >=4.8.34 <4.8.34.5 || >=4.8.37 <4.8.37.4 | 4.8.14.4, 4.8.19.8, 4.8.21.10, 4.8.28.4, 4.8.30.6, 4.8.32.4, 4.8.33.4, 4.8.34.5, 4.8.37.4 |
| WSO2/WSO2 Carbon Governance Life Cycles User Interfacegeneric | >=4.8.14 <4.8.14.4 || >=4.8.19 <4.8.19.8 || >=4.8.21 <4.8.21.10 || >=4.8.28 <4.8.28.4 || >=4.8.30 <4.8.30.6 || >=4.8.32 <4.8.32.4 | 4.8.14.4, 4.8.19.8, 4.8.21.10, 4.8.28.4, 4.8.30.6, 4.8.32.4 |
| WSO2/WSO2 Carbon Governance WSDL Tool UIgeneric | >=4.8.14 <4.8.14.4 || >=4.8.19 <4.8.19.8 || >=4.8.21 <4.8.21.10 || >=4.8.28 <4.8.28.4 || >=4.8.30 <4.8.30.6 || >=4.8.32 <4.8.32.4 || >=4.8.33 <4.8.33.4 || >=4.8.34 <4.8.34.5 || >=4.8.37 <4.8.37.4 | 4.8.14.4, 4.8.19.8, 4.8.21.10, 4.8.28.4, 4.8.30.6, 4.8.32.4, 4.8.33.4, 4.8.34.5, 4.8.37.4 |
| WSO2/WSO2 Carbon HL7 Business Messaging Store UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon HumanTask UIgeneric | >=4.5.27 <4.5.27.10 | 4.5.27.10 |
| WSO2/WSO2 Carbon Identity Entitlement UIgeneric | >=5.17.5 <5.17.5.331 || >=5.18.187 <5.18.187.329 || >=5.23.8 <5.23.8.210 || >=5.25.92 <5.25.92.166 || >=7.0.78 <7.0.78.157 | 5.17.5.331, 5.18.187.329, 5.23.8.210, 5.25.92.166, 7.0.78.157 |
| WSO2/WSO2 Carbon Identity Management UI1generic | >=5.17.5 <5.17.5.330 || >=5.17.5 <5.17.5.331 || >=5.17.118 <5.17.118.22 || >=5.18.187 <5.18.187.328 || >=5.18.187 <5.18.187.329 || >=5.18.248 <5.18.248.31 || >=5.23.8 <5.23.8.210 || >=5.24.8 <5.24.8.26 || >=5.25.92 <5.25.92.166 || >=5.25.705 <5.25.705.21 || >=5.25.713 <5.25.713.10 || >=5.25.724 <5.25.724.5 || >=5.25.736 <5.25.736.1 || >=7.0.78 <7.0.78.157 || >=7.8.23 <7.8.23.67 || >=7.8.586 <7.8.586.7 | 5.17.5.330, 5.17.5.331, 5.17.118.22, 5.18.187.328, 5.18.187.329, 5.18.248.31, 5.23.8.210, 5.24.8.26, 5.25.92.166, 5.25.705.21, 5.25.713.10, 5.25.724.5, 5.25.736.1, 7.0.78.157, 7.8.23.67, 7.8.586.7 |
| WSO2/WSO2 Carbon Identity User Store Configuration UIgeneric | >=5.14.127 <5.14.127.13 || >=5.17.5 <5.17.5.330 || >=5.17.5 <5.17.5.331 || >=5.17.118 <5.17.118.22 || >=5.18.187 <5.18.187.328 || >=5.18.187 <5.18.187.329 || >=5.18.248 <5.18.248.31 || >=5.23.8 <5.23.8.210 || >=5.24.8 <5.24.8.26 || >=5.25.92 <5.25.92.166 || >=5.25.705 <5.25.705.21 || >=5.25.713 <5.25.713.10 || >=5.25.724 <5.25.724.5 || >=5.25.736 <5.25.736.1 || >=7.0.78 <7.0.78.157 || >=7.8.23 <7.8.23.67 || >=7.8.586 <7.8.586.7 | 5.14.127.13, 5.17.5.330, 5.17.5.331, 5.17.118.22, 5.18.187.328, 5.18.187.329, 5.18.248.31, 5.23.8.210, 5.24.8.26, 5.25.92.166, 5.25.705.21, 5.25.713.10, 5.25.724.5, 5.25.736.1, 7.0.78.157, 7.8.23.67, 7.8.586.7 |
| WSO2/WSO2 Carbon Logging UIgeneric | >=4.7.19 <4.7.19.13 || >=4.7.24 <4.7.24.5 || >=4.7.32 <4.7.32.10 || >=4.7.52 <4.7.52.5 | 4.7.19.13, 4.7.24.5, 4.7.32.10, 4.7.52.5 |
| WSO2/WSO2 Carbon New Data Sources UIgeneric | >=4.7.19 <4.7.19.13 || >=4.7.24 <4.7.24.5 || >=4.7.32 <4.7.32.10 || >=4.7.35 <4.7.35.13 || >=4.7.49 <4.7.49.7 || >=4.7.52 <4.7.52.5 || >=4.9.2 <4.9.2.8 || >=4.9.11 <4.9.11.2 || >=4.9.18 <4.9.18.1 | 4.7.19.13, 4.7.24.5, 4.7.32.10, 4.7.35.13, 4.7.49.7, 4.7.52.5, 4.9.2.8, 4.9.11.2, 4.9.18.1 |
| WSO2/WSO2 Carbon Publish Event Mediator Configuration UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Registry Indexinggeneric | >=4.7 <4.7.24 | 4.7.24 |
| WSO2/WSO2 Carbon Registry Info UI2generic | >=4.7.32 <4.7.32.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.13 <4.8.13.9 || >=4.8.32 <4.8.32.4 || >=4.8.36 <4.8.36.2 || >=4.8.43 <4.8.43.2 || >=4.8.50 <4.8.50.1 | 4.7.32.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.13.9, 4.8.32.4, 4.8.36.2, 4.8.43.2, 4.8.50.1 |
| WSO2/WSO2 Carbon Registry Profiles UIgeneric | >=4.7.32 <4.7.32.18 || >=4.7.33 <4.7.33.16 || >=4.8.9 <4.8.9.16 || >=4.8.12 <4.8.12.8 || >=4.8.24 <4.8.24.6 || >=4.8.43 <4.8.43.4 || >=4.8.50 <4.8.50.3 | 4.7.32.18, 4.7.33.16, 4.8.9.16, 4.8.12.8, 4.8.24.6, 4.8.43.4, 4.8.50.3 |
| WSO2/WSO2 Carbon Registry Properties UIgeneric | >=4.7.24 <4.7.24.11 || >=4.7.32 <4.7.32.16 || >=4.7.32 <4.7.32.18 || >=4.7.33 <4.7.33.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.9 <4.8.9.16 || >=4.8.12 <4.8.12.8 || >=4.8.13 <4.8.13.9 || >=4.8.24 <4.8.24.6 || >=4.8.32 <4.8.32.4 || >=4.8.36 <4.8.36.2 || >=4.8.43 <4.8.43.2 || >=4.8.43 <4.8.43.4 || >=4.8.50 <4.8.50.1 || >=4.8.50 <4.8.50.3 | 4.7.24.11, 4.7.32.16, 4.7.32.18, 4.7.33.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.9.16, 4.8.12.8, 4.8.13.9, 4.8.24.6, 4.8.32.4, 4.8.36.2, 4.8.43.2, 4.8.43.4, 4.8.50.1, 4.8.50.3 |
| WSO2/WSO2 Carbon Registry Relations UIgeneric | >=4.7.24 <4.7.24.11 || >=4.7.32 <4.7.32.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.13 <4.8.13.9 || >=4.8.32 <4.8.32.4 || >=4.8.36 <4.8.36.2 || >=4.8.43 <4.8.43.2 || >=4.8.50 <4.8.50.1 | 4.7.24.11, 4.7.32.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.13.9, 4.8.32.4, 4.8.36.2, 4.8.43.2, 4.8.50.1 |
| WSO2/WSO2 Carbon Registry Resources UIgeneric | >=4.7.24 <4.7.24.11 || >=4.7.32 <4.7.32.16 || >=4.7.32 <4.7.32.18 || >=4.7.33 <4.7.33.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.9 <4.8.9.16 || >=4.8.12 <4.8.12.8 || >=4.8.13 <4.8.13.9 || >=4.8.24 <4.8.24.6 || >=4.8.32 <4.8.32.4 || >=4.8.36 <4.8.36.2 || >=4.8.43 <4.8.43.2 || >=4.8.43 <4.8.43.4 || >=4.8.50 <4.8.50.1 || >=4.8.50 <4.8.50.3 | 4.7.24.11, 4.7.32.16, 4.7.32.18, 4.7.33.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.9.16, 4.8.12.8, 4.8.13.9, 4.8.24.6, 4.8.32.4, 4.8.36.2, 4.8.43.2, 4.8.43.4, 4.8.50.1, 4.8.50.3 |
| WSO2/WSO2 Carbon Registry Search UIgeneric | >=4.7.24 <4.7.24.11 || >=4.7.32 <4.7.32.16 || >=4.7.32 <4.7.32.18 || >=4.7.33 <4.7.33.16 || >=4.7.35 <4.7.35.15 || >=4.7.39 <4.7.39.12 || >=4.7.51 <4.7.51.8 || >=4.8.3 <4.8.3.10 || >=4.8.9 <4.8.9.16 || >=4.8.12 <4.8.12.8 || >=4.8.13 <4.8.13.9 || >=4.8.24 <4.8.24.6 | 4.7.24.11, 4.7.32.16, 4.7.32.18, 4.7.33.16, 4.7.35.15, 4.7.39.12, 4.7.51.8, 4.8.3.10, 4.8.9.16, 4.8.12.8, 4.8.13.9, 4.8.24.6 |
| WSO2/WSO2 Carbon Rest API Admin UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Rule Mediator UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Security UIgeneric | >=5.14 <5.14.127 | 5.14.127 |
| WSO2/WSO2 Carbon Sequence Editor UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Tasks Coregeneric | >=4.7.19 <4.7.19.13 | 4.7.19.13 |
| WSO2/WSO2 Carbon Task UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Template Editor UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Carbon Throttle Mediator UIgeneric | >=4.7.30 <4.7.30.53 | 4.7.30.53 |
| WSO2/WSO2 Enterprise Integratorgeneric | >=6.6.0 <6.6.0.227 | 6.6.0.227 |
| WSO2/WSO2 Identity Servergeneric | >=5.10.0 <5.10.0.381 || >=5.11.0 <5.11.0.428 || >=6.0.0 <6.0.0.255 || >=6.1.0 <6.1.0.256 || >=7.0.0 <7.0.0.133 || >=7.1.0 <7.1.0.41 || >=7.2.0 <7.2.0.3 | 5.10.0.381, 5.11.0.428, 6.0.0.255, 6.1.0.256, 7.0.0.133, 7.1.0.41, 7.2.0.3 |
| WSO2/WSO2 Identity Server as Key Managergeneric | >=5.10.0 <5.10.0.372 | 5.10.0.372 |
| WSO2/WSO2 Open Banking AMgeneric | >=2.0.0 <2.0.0.401 | 2.0.0.401 |
| WSO2/WSO2 Open Banking IAMgeneric | >=2.0.0 <2.0.0.421 | 2.0.0.421 |
| WSO2/WSO2 Stratos SSO Redirector UI Componentgeneric | >=4.8.1 <4.8.1.6 | 4.8.1.6 |
| WSO2/WSO2 Stratos User Interface For Tenant CRUD Operationsgeneric | >=4.8.1 <4.8.1.6 || >=4.8.7 <4.8.7.3 || >=4.9.8 <4.9.8.7 || >=4.9.10 <4.9.10.7 || >=4.9.10 <4.9.10.8 || >=4.9.20 <4.9.20.5 || >=4.9.27 <4.9.27.1 || >=4.9.31 <4.9.31.1 || >=4.9.34 <4.9.34.1 || >=4.9.42 <4.9.42.1 || >=4.11.0 <4.11.0.7 || >=4.11.19 <4.11.19.4 || >=4.11.34 <4.11.34.3 || >=4.11.45 <4.11.45.1 | 4.8.1.6, 4.8.7.3, 4.9.8.7, 4.9.10.7, 4.9.10.8, 4.9.20.5, 4.9.27.1, 4.9.31.1, 4.9.34.1, 4.9.42.1, 4.11.0.7, 4.11.19.4, 4.11.34.3, 4.11.45.1 |
| WSO2/WSO2 Traffic Managergeneric | >=4.5.0 <4.5.0.37 || >=4.6.0 <4.6.0.3 | 4.5.0.37, 4.6.0.3 |
| WSO2/WSO2 Universal Gatewaygeneric | >=4.5.0 <4.5.0.37 || >=4.6.0 <4.6.0.3 | 4.5.0.37, 4.6.0.3 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions. An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.
Quoted source text, attributed separately from HOL analysis.