Answer in brief
CVE-2026-3096 records a Unknown severity vulnerability in Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.54 || >=4.6.0 <4.6.0.18 | 4.5.0.54, 4.6.0.18 |
| WSO2/WSO2 API Managergeneric | >=3.2.0 <3.2.0.468 || >=3.2.1 <3.2.1.87 || >=4.1.0 <4.1.0.252 || >=4.2.0 <4.2.0.192 || >=4.3.0 <4.3.0.103 || >=4.4.0 <4.4.0.67 || >=4.5.0 <4.5.0.52 || >=4.6.0 <4.6.0.16 | 3.2.0.468, 3.2.1.87, 4.1.0.252, 4.2.0.192, 4.3.0.103, 4.4.0.67, 4.5.0.52, 4.6.0.16 |
Published upstream
Sep 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 10, 2026
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.
Quoted source text, attributed separately from HOL analysis.