CVE-2026-3096: Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations.
This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker needs to persuade a user to click a malicious external link that opens in a new browser tab. Exploitation relies on the browser contexts retaining the ability to interact after that navigation.
Which deployments are exposed?
WSO2 web portals are affected when configured to open external links in a new tab while allowing the originating window to retain access to the newly opened page. The provided information does not state that all default portal configurations are affected.
How can I determine whether my portal is affected?
Review or test external-link behavior in the portal. A deployment is in scope if an external destination opens in a new tab and the original trusted portal window can still interact with that tab after navigation.