boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-3416

WSO2 WSO2 API Manager — Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0036   27.3     —
AFFECTED
  Product                 Versions  Fixed
  WSO2 API Manager        4.1.0 –   —
  WSO2 API Control Plane  4.5.0 –   —
TIMELINE
  Mar 1   Reserved by WSO2
  Sep 3   Published (CNA: WSO2)
  Sep 15  RESCORED — CVE-2026-3416 (WSO2 API Manager). CVSS 5.9 → 7.5 (NVD).
CWE-330 · CNA: WSO2 · CVSS v3.1 · 1 reference · NVD status: Analyzed

Description

The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification. Successful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 1, 2026ReservedReserved by WSO2
September 3, 2026PublishedPublished (CNA: WSO2)
September 15, 2026RESCOREDRESCORED — CVE-2026-3416 (WSO2 API Manager). CVSS 5.9 → 7.5 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
WSO2WSO2 API Manager—4.1.0—
WSO2WSO2 API Control Plane—4.5.0—

Weaknesses

CWE-330

References (1)

Related

Authoritative record: CVE-2026-3416 at cve.org

Vendors: wso2

Weaknesses: CWE-330

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-3416 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.