← Back to CVEs
CVE-2025-9804
CRITICAL9.6
Description
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
CVE Details
CVSS v3.1 Score9.6
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published10/16/2025
Last Modified11/21/2025
Sourcenvd
Honeypot Sightings0
Affected Products
wso2:api_control_planewso2:api_managerwso2:api_manager_analyticswso2:data_analytics_serverwso2:enterprise_integratorwso2:enterprise_mobility_managerwso2:enterprise_service_buswso2:identity_serverwso2:identity_server_analyticswso2:identity_server_as_key_managerwso2:open_banking_amwso2:open_banking_iamwso2:open_banking_kmwso2:traffic_managerwso2:universal_gateway
Weaknesses (CWE)
CWE-284
References
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4503/(ed10eef1-636d-4fbe-9993-6890dfa878f8)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.