AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2024-6541

MEDIUM · CVSS 6.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability arises from the Class Mediator's inadequate validation of `messageContext` properties, which may allow authenticated users to access or modify data across isolated system invocations. This could lead to unauthorized disclosure of sensitive information or unintended data modifications. Organizations using WSO2 products that implement this functionality should prioritize remediation to mitigate potential data breaches and integrity issues.

CVE
CVE-2024-6541
Severity
MEDIUM
CVSS
6.8
EPSS
0.26%

Original NVD Description

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.