Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(no matching packages found)
Permalink CVE-2026-1728
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

Affected products

WSO2 API Manager
  • <4.0.0.384
  • <4.1.0.248
  • <4.5.0.48
  • <4.2.0.188
  • <4.0.0
  • <4.4.0.63
  • <4.6.0.12
  • <4.3.0.99
WSO2 Traffic Manager
  • <4.5.0.47
  • <4.6.0.12
WSO2 API Control Plane
  • <4.6.0.13
  • <4.5.0.49
WSO2 Universal Gateway
  • <4.6.0.12
  • <4.5.0.48
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util
  • =<*
  • <9.20.74.392
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.common
  • <9.31.86.130
  • =<*
  • <9.30.67.146
  • <9.29.120.221
  • <9.0.174.550
  • <9.32.147.26
  • <9.28.116.404