CVE-2026-1728

Summary

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.

Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

Affected Software

VendorProductVersion RangeStatus
WSO2WSO2 API Manager0 < 4.0.0unknown
WSO2WSO2 API Manager4.0.0 < 4.0.0.384affected
WSO2WSO2 API Manager4.1.0 < 4.1.0.248affected
WSO2WSO2 API Manager4.2.0 < 4.2.0.188affected
WSO2WSO2 API Manager4.3.0 < 4.3.0.99affected
WSO2WSO2 API Manager4.4.0 < 4.4.0.63affected
WSO2WSO2 API Manager4.5.0 < 4.5.0.48affected
WSO2WSO2 API Manager4.6.0 < 4.6.0.12affected
WSO2WSO2 API Control Plane4.5.0 < 4.5.0.49affected
WSO2WSO2 API Control Plane4.6.0 < 4.6.0.13affected
WSO2WSO2 Universal Gateway4.5.0 < 4.5.0.48affected
WSO2WSO2 Universal Gateway4.6.0 < 4.6.0.12affected
WSO2WSO2 Traffic Manager4.5.0 < 4.5.0.47affected
WSO2WSO2 Traffic Manager4.6.0 < 4.6.0.12affected
WSO2WSO2 Carbon API Manager Rest API Common Functions9.0.174 < 9.0.174.550affected
WSO2WSO2 Carbon API Manager Rest API Common Functions9.28.116 < 9.28.116.404affected
WSO2WSO2 Carbon API Manager Rest API Common Functions9.29.120 < 9.29.120.221affected
WSO2WSO2 Carbon API Manager Rest API Common Functions9.30.67 < 9.30.67.146affected
WSO2WSO2 Carbon API Manager Rest API Common Functions9.31.86 < 9.31.86.130affected
WSO2WSO2 Carbon API Manager Rest API Common Functions9.32.147 < 9.32.147.26affected
WSO2WSO2 Carbon API Manager Rest API Common Functions9.33.27 <= *unaffected
WSO2WSO2 Carbon API Manager Rest API Utility9.20.74 < 9.20.74.392affected
WSO2WSO2 Carbon API Manager Rest API Utility9.33.27 <= *unaffected

Weaknesses

  • CWE-269: CWE-269: Improper Privilege Management

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References