Skip to content
Reflected XSS Vulnerability in WSO2 API Manager 2.6.0 Discovered

Reflected XSS Vulnerability in WSO2 API Manager 2.6.0 Discovered

First seen 9 Jun 2026, 00:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 10, 2026 at 00:16 UTC
  • CVE-2019-20435 is a reflected XSS vulnerability in WSO2 API Manager 2.6.0.
  • Attackers can exploit this vulnerability via malicious HTTP GET requests.
  • Users are urged to apply the relevant patches to protect their systems.

A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2019-20435, was discovered in WSO2 API Manager version 2.6.0. This vulnerability allows attackers to exploit the inline API documentation editor page of the API Publisher by sending a malicious HTTP GET request with a harmful 'docName' parameter. The attack requires only LAN or WiFi adjacency to be successful. The vulnerability has been reproduced in a sandboxed environment, indicating its potential for exploitation. Affected users are advised to download the relevant patch based on their product version. The CVE was published on January 27, 2020, and has been updated in the NVD as of June 9, 2026. Security professionals should prioritize applying the patch to mitigate risks associated with this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2020-01-27
CVE-2019-20435 published
The vulnerability in WSO2 API Manager was officially published, detailing the XSS issue.
nvd.nist.gov
2026-06-08
Vulnerability discovered
Securin reported the reflected XSS vulnerability in WSO2 API Manager's inline documentation editor.
Securin
2026-06-09
NVD enrichment update
The NVD updated the CVE record to reflect new enrichment efforts and details about the vulnerability.
nvd.nist.gov

More articles in this cluster (2)

Following this threat?

Track WSO2 and CVE-2019-20435 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed