Dismissed
(no matching packages found)
Permalink
CVE-2026-1728
9.8 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created & dismissed (no matching packages found) suggestion
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
References
Affected products
WSO2 API Manager
- <4.0.0.384
- <4.1.0.248
- <4.5.0.48
- <4.2.0.188
- <4.0.0
- <4.4.0.63
- <4.6.0.12
- <4.3.0.99
WSO2 Traffic Manager
- <4.5.0.47
- <4.6.0.12
WSO2 API Control Plane
- <4.6.0.13
- <4.5.0.49
WSO2 Universal Gateway
- <4.6.0.12
- <4.5.0.48
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util
- =<*
- <9.20.74.392
org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.common
- <9.31.86.130
- =<*
- <9.30.67.146
- <9.29.120.221
- <9.0.174.550
- <9.32.147.26
- <9.28.116.404