The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated.

This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.

Project Subscriptions

Vendors Products
Micro Integrator Subscribe
Wso2-synapse Subscribe
Wso2 Api Manager Subscribe
Wso2 Enterprise Integrator Subscribe
Wso2 Micro Integrator Subscribe
Advisories

No advisories yet.

Fixes

Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3520/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3520/#solution


Workaround

No workaround given by the vendor.

History

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 micro Integrator
Vendors & Products Wso2 micro Integrator

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.
Title Information Disclosure and Integrity Violation via Improper Message Context Handling in Multiple WSO2 Products
First Time appeared Wso2
Wso2 wso2-synapse
Wso2 wso2 Api Manager
Wso2 wso2 Enterprise Integrator
Wso2 wso2 Micro Integrator
Weaknesses CWE-20
CPEs cpe:2.3:a:wso2:wso2-synapse:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_enterprise_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_micro_integrator:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2-synapse
Wso2 wso2 Api Manager
Wso2 wso2 Enterprise Integrator
Wso2 wso2 Micro Integrator
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-07T17:45:43.395Z

Reserved: 2024-07-08T09:20:26.394Z

Link: CVE-2024-6541

cve-icon Vulnrichment

Updated: 2026-08-07T17:45:37.776Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:59:13Z

Weaknesses