CVE-2025-9804Critical· 9.6▾ MidnightAn improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform una…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information.
This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
api_control_plane = 4.5.0api_manager = 2.0.0api_manager = 2.1.0api_manager = 2.2.0api_manager = 2.5.0api_manager = 2.6.0api_manager = 3.0.0api_manager = 3.1.0api_manager = 3.2.0api_manager = 3.2.1api_manager = 4.0.0api_manager = 4.1.0api_manager = 4.2.0api_manager = 4.3.0api_manager = 4.4.0api_manager = 4.5.0api_manager_analytics = 2.0.0api_manager_analytics = 2.1.0api_manager_analytics = 2.2.0api_manager_analytics = 2.5.0data_analytics_server = 3.1.0data_analytics_server = 3.2.0enterprise_integrator = 6.2.0enterprise_integrator = 6.3.0enterprise_mobility_manager = 2.2.0enterprise_service_bus = 5.0.0identity_server = 5.2.0identity_server = 5.3.0identity_server = 5.4.0identity_server = 5.4.1identity_server = 5.5.0identity_server = 5.6.0identity_server = 5.7.0identity_server = 5.8.0identity_server = 5.9.0identity_server = 5.10.0identity_server = 5.11.0identity_server = 6.0.0identity_server = 6.1.0identity_server = 7.0.0identity_server = 7.1.0identity_server_analytics = 5.2.0identity_server_analytics = 5.3.0identity_server_analytics = 5.5.0identity_server_analytics = 5.6.0identity_server_as_key_manager = 5.3.0identity_server_as_key_manager = 5.5.0identity_server_as_key_manager = 5.6.0identity_server_as_key_manager = 5.7.0identity_server_as_key_manager = 5.9.0identity_server_as_key_manager = 5.10.0open_banking_am = 1.4.0open_banking_am = 1.5.0open_banking_am = 2.0.0open_banking_iam = 2.0.0open_banking_km = 1.4.0open_banking_km = 1.5.0traffic_manager = 4.5.0universal_gateway = 4.5.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5430Critical· 10.0The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported
CVE-2026-3416Medium· 5.9The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation
CVE-2025-12737High· 8.4The administrative operations within the Carbon Console do not adequately validate specific user-supplied input
CVE-2024-6832Medium· 5.9The account locking mechanism fails to trigger when secondary user stores are inaccessible
CVE-2024-10302Medium· 4.0The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input
CVE-2026-1609High· 8.1A flaw was found in Keycloak