WSO2 API Manager Improper Privilege Management Vulnerability in Dynamic Client Registration Endpoint

Vulnerability

A vulnerability allowing improper privilege management has been identified in WSO2 API Manager versions 4.5.0, 4.4.0, 4.3.0, 4.2.0, 4.1.0, 4.0.0, 3.2.1, and 3.2.0. This vulnerability arises from inadequate authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. As a result, malicious users can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.

Impact

Exploitation of this vulnerability could allow an attacker to gain administrative privileges and execute unauthorized actions within the application.

Remediation

Users of WSO2 API Manager can update to version 4.5.0, 4.4.0, 4.3.0, 4.2.0, 4.1.0, 4.0.0, 3.2.1, or 3.2.0. Community users can apply the public fix available on GitHub. WSO2 Support Subscription Holders can use WSO2 Updates to apply the fix.

Added: Oct 16, 2025, 1:19 PM
Updated: Oct 16, 2025, 3:42 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
7.6
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.