Reflected XSS Vulnerability in WSO2 API Manager 2.6.0 Discovered

Reflected XSS Vulnerability in WSO2 API Manager 2.6.0 Discovered

First seen 9 Jun 2026, 00:28 UTC Securinnvd.nist.gov 82% similarity 57.8

Article Content

Browse articles
ThreatCluster

A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2019-20435, was discovered in WSO2 API Manager version 2.6.0. This vulnerability allows attackers to exploit the inline API documentation editor page of the API Publisher by sending a malicious HTTP GET request with a harmful 'docName' parameter. The attack requires only LAN or WiFi adjacency to be successful. The vulnerability has been reproduced in a sandboxed environment, indicating its potential for exploitation. Affected users are advised to download the relevant patch based on their product version. The CVE was published on January 27, 2020, and has been updated in the NVD as of June 9, 2026. Security professionals should prioritize applying the patch to mitigate risks associated with this vulnerability.

Key Points: • CVE-2019-20435 is a reflected XSS vulnerability in WSO2 API Manager 2.6.0. • Attackers can exploit this vulnerability via malicious HTTP GET requests. • Users are urged to apply the relevant patches to protect their systems.

ThreatCluster AI

Timeline

2020-01-27
CVE-2019-20435 published
The vulnerability in WSO2 API Manager was officially published, detailing the XSS issue.
nvd.nist.gov
2026-06-08
Vulnerability discovered
Securin reported the reflected XSS vulnerability in WSO2 API Manager's inline documentation editor.
Securin
2026-06-09
NVD enrichment update
The NVD updated the CVE record to reflect new enrichment efforts and details about the vulnerability.
nvd.nist.gov

Community

Browse all →

Tracked Entities in This Story