Answer in brief
CVE-2026-4103 records a Unknown severity vulnerability in Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.55 || >=4.6.0 <4.6.0.19 | 4.5.0.55, 4.6.0.19 |
| WSO2/WSO2 API Managergeneric | >=3.2.0 <3.2.0.470 || >=3.2.1 <3.2.1.89 || >=4.1.0 <4.1.0.254 || >=4.2.0 <4.2.0.194 || >=4.3.0 <4.3.0.105 || >=4.4.0 <4.4.0.69 || >=4.5.0 <4.5.0.54 || >=4.6.0 <4.6.0.18 | 3.2.0.470, 3.2.1.89, 4.1.0.254, 4.2.0.194, 4.3.0.105, 4.4.0.69, 4.5.0.54, 4.6.0.18 |
Published upstream
Sep 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 14, 2026
Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API documents are viewed. Successful exploitation may result in the execution of malicious scripts within the user's browser context when viewing API documentation. Users with permissions to access the API documentation through these portals may be impacted, potentially allowing attackers to perform actions on behalf of the user, depending on their session privileges.
Quoted source text, attributed separately from HOL analysis.