CVE-2026-3096: Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft

Published Sep 10, 2026
·
Updated

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations.

This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.

Affected Software

1 affected component
WSO2 WSO2 web portals

Event History

Sep 10, 2026
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker do to exploit this issue?

The attacker needs to persuade a user to click a malicious external link that opens in a new browser tab. Exploitation relies on the browser contexts retaining the ability to interact after that navigation.

2

Which deployments are exposed?

WSO2 web portals are affected when configured to open external links in a new tab while allowing the originating window to retain access to the newly opened page. The provided information does not state that all default portal configurations are affected.

3

How can I determine whether my portal is affected?

Review or test external-link behavior in the portal. A deployment is in scope if an external destination opens in a new tab and the original trusted portal window can still interact with that tab after navigation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203