Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-3096— Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft

Quick assessment

Affected
WSO2 WSO2 API Control Plane
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

该产品的 Web 门户允许在新浏览器标签页中打开外部链接。在某些配置下,源窗口保留对新打开页面的访问权限,使得在导航到外部目标时,两个浏览器上下文之间可以相互交互。 该漏洞可能允许攻击者在用户点击恶意外部链接后,操控原本受信任的应用程序窗口。这种操控可能导致用户被重定向到钓鱼页面,从而造成凭证被盗取,或在受信任网站的上下文中促成其他未授权的操作。

CVSS 4.7 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-3096

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
Source: CVE Program / CVE List V5
Vulnerability Description
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WSO2 WSO2 API Control Plane 4.5.0 ~ 4.5.0.54 -
WSO2 WSO2 API Manager 3.2.0 ~ 3.2.0.468 -

II. Public POCs for CVE-2026-3096

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-3096

登录查看更多情报信息。

Vendor Advisories for CVE-2026-3096 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-3096

No comments yet


Leave a comment