Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-3416
WSO2 WSO2 API Manager — Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .0036 27.3 —
AFFECTED
Product Versions Fixed
WSO2 API Manager 4.1.0 – —
WSO2 API Control Plane 4.5.0 – —
TIMELINE
Mar 1 Reserved by WSO2
Sep 3 Published (CNA: WSO2)
Sep 15 RESCORED — CVE-2026-3416 (WSO2 API Manager). CVSS 5.9 → 7.5 (NVD).
Description
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification.
Successful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 1, 2026 | Reserved | Reserved by WSO2 |
| September 3, 2026 | Published | Published (CNA: WSO2) |
| September 15, 2026 | RESCORED | RESCORED — CVE-2026-3416 (WSO2 API Manager). CVSS 5.9 → 7.5 (NVD). |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| WSO2 | WSO2 API Manager | — | 4.1.0 | — |
| WSO2 | WSO2 API Control Plane | — | 4.5.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-3416 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.