Answer in brief
CVE-2026-3415 records a High severity (CVSS 8.7) vulnerability in XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon API Gateway (generic), WSO2/WSO2 Carbon API Management Implementation (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon API Gateway (generic), WSO2/WSO2 Carbon API Management Implementation (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.54 || >=4.6.0 <4.6.0.17 | 4.5.0.54, 4.6.0.17 |
| WSO2/WSO2 API Managergeneric | >=3.2.0 <3.2.0.472 || >=3.2.1 <3.2.1.91 || >=4.1.0 <4.1.0.254 || >=4.2.0 <4.2.0.194 || >=4.3.0 <4.3.0.105 || >=4.4.0 <4.4.0.68 || >=4.5.0 <4.5.0.53 || >=4.6.0 <4.6.0.16 | 3.2.0.472, 3.2.1.91, 4.1.0.254, 4.2.0.194, 4.3.0.105, 4.4.0.68, 4.5.0.53, 4.6.0.16 |
| WSO2/WSO2 Carbon API Gatewaygeneric | >=6.7.206 <6.7.206.594 || >=6.7.210 <6.7.210.95 || >=9.20.74 <9.20.74.398 || >=9.28.116 <9.28.116.412 || >=9.29.120 <9.29.120.228 || >=9.30.67 <9.30.67.158 || >=9.31.86 <9.31.86.147 || >=9.32.147 <9.32.147.38 | 6.7.206.594, 6.7.210.95, 9.20.74.398, 9.28.116.412, 9.29.120.228, 9.30.67.158, 9.31.86.147, 9.32.147.38 |
| WSO2/WSO2 Carbon API Management Implementationgeneric | >=6.7.206 <6.7.206.594 || >=6.7.210 <6.7.210.95 || >=9.20.74 <9.20.74.398 || >=9.28.116 <9.28.116.412 || >=9.29.120 <9.29.120.228 || >=9.30.67 <9.30.67.158 || >=9.31.86 <9.31.86.147 || >=9.32.147 <9.32.147.38 | 6.7.206.594, 6.7.210.95, 9.20.74.398, 9.28.116.412, 9.29.120.228, 9.30.67.158, 9.31.86.147, 9.32.147.38 |
| WSO2/WSO2 Traffic Managergeneric | >=4.5.0 <4.5.0.52 || >=4.6.0 <4.6.0.16 | 4.5.0.52, 4.6.0.16 |
| WSO2/WSO2 Universal Gatewaygeneric | >=4.5.0 <4.5.0.53 || >=4.6.0 <4.6.0.16 | 4.5.0.53, 4.6.0.16 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges. Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-3415 records a High severity (CVSS 8.7) vulnerability in XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon API Gateway (generic), WSO2/WSO2 Carbon API Management Implementation (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon API Gateway (generic), WSO2/WSO2 Carbon API Management Implementation (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.54 || >=4.6.0 <4.6.0.17 | 4.5.0.54, 4.6.0.17 |
| WSO2/WSO2 API Managergeneric | >=3.2.0 <3.2.0.472 || >=3.2.1 <3.2.1.91 || >=4.1.0 <4.1.0.254 || >=4.2.0 <4.2.0.194 || >=4.3.0 <4.3.0.105 || >=4.4.0 <4.4.0.68 || >=4.5.0 <4.5.0.53 || >=4.6.0 <4.6.0.16 | 3.2.0.472, 3.2.1.91, 4.1.0.254, 4.2.0.194, 4.3.0.105, 4.4.0.68, 4.5.0.53, 4.6.0.16 |
| WSO2/WSO2 Carbon API Gatewaygeneric | >=6.7.206 <6.7.206.594 || >=6.7.210 <6.7.210.95 || >=9.20.74 <9.20.74.398 || >=9.28.116 <9.28.116.412 || >=9.29.120 <9.29.120.228 || >=9.30.67 <9.30.67.158 || >=9.31.86 <9.31.86.147 || >=9.32.147 <9.32.147.38 | 6.7.206.594, 6.7.210.95, 9.20.74.398, 9.28.116.412, 9.29.120.228, 9.30.67.158, 9.31.86.147, 9.32.147.38 |
| WSO2/WSO2 Carbon API Management Implementationgeneric | >=6.7.206 <6.7.206.594 || >=6.7.210 <6.7.210.95 || >=9.20.74 <9.20.74.398 || >=9.28.116 <9.28.116.412 || >=9.29.120 <9.29.120.228 || >=9.30.67 <9.30.67.158 || >=9.31.86 <9.31.86.147 || >=9.32.147 <9.32.147.38 | 6.7.206.594, 6.7.210.95, 9.20.74.398, 9.28.116.412, 9.29.120.228, 9.30.67.158, 9.31.86.147, 9.32.147.38 |
| WSO2/WSO2 Traffic Managergeneric | >=4.5.0 <4.5.0.52 || >=4.6.0 <4.6.0.16 | 4.5.0.52, 4.6.0.16 |
| WSO2/WSO2 Universal Gatewaygeneric | >=4.5.0 <4.5.0.53 || >=4.6.0 <4.6.0.16 | 4.5.0.53, 4.6.0.16 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges. Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.
Quoted source text, attributed separately from HOL analysis.