Executive brief
A security vulnerability exists in the Symantec API Gateway, a tool used to manage and secure communications between different software applications. An attacker who is able to intercept network traffic between a client and the gateway could manipulate data to run unauthorized commands. This could lead to a complete takeover of the gateway or unauthorized access to sensitive business data.
Technical details
The Symantec API Gateway is vulnerable to the deserialization of untrusted data (CWE-502). The vulnerability occurs when the server processes manipulated traffic intercepted between a client application and the API Gateway. An attacker with low privileges and the ability to perform a man-in-the-middle (MitM) attack or otherwise intercept network traffic can inject malicious serialized objects. Successful exploitation can lead to broken security expectations or full remote code execution (RCE) on the gateway server. The attack complexity is considered high as it requires the attacker to be in a position to intercept and modify active traffic.
Affected products
- Symantec API Gateway
Timeline
- 2026-06-10: advisory: Initial advisory published by Symantec/Broadcom