WSO2 Products Improper Access Control Vulnerability in Internal APIs

Vulnerability

A vulnerability allowing improper access control has been identified in multiple WSO2 products. This issue arises from inadequate permission enforcement in certain internal SOAP Admin Services and System REST APIs, allowing low-privileged users to perform unauthorized operations, such as accessing server-level information. The vulnerability is limited to internal administrative interfaces, with APIs exposed through the WSO2 API Manager's API Gateway remaining unaffected.

Impact

Exploitation of this vulnerability could enable unauthorized users to perform restricted actions or access sensitive server-level information on the affected WSO2 product.

Remediation

Users can apply the relevant fixes available on GitHub for their specific WSO2 product version. For WSO2 Support Subscription Holders, updates can be applied through the WSO2 Updates service.

Added: Oct 16, 2025, 1:18 PM
Updated: Oct 16, 2025, 3:42 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
3.1
exploitability
4.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.