CVE-2026-1728
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WSO2 | WSO2 API Manager | 0 < 4.0.0 | unknown |
| WSO2 | WSO2 API Manager | 4.0.0 < 4.0.0.384 | affected |
| WSO2 | WSO2 API Manager | 4.1.0 < 4.1.0.248 | affected |
| WSO2 | WSO2 API Manager | 4.2.0 < 4.2.0.188 | affected |
| WSO2 | WSO2 API Manager | 4.3.0 < 4.3.0.99 | affected |
| WSO2 | WSO2 API Manager | 4.4.0 < 4.4.0.63 | affected |
| WSO2 | WSO2 API Manager | 4.5.0 < 4.5.0.48 | affected |
| WSO2 | WSO2 API Manager | 4.6.0 < 4.6.0.12 | affected |
| WSO2 | WSO2 API Control Plane | 4.5.0 < 4.5.0.49 | affected |
| WSO2 | WSO2 API Control Plane | 4.6.0 < 4.6.0.13 | affected |
| WSO2 | WSO2 Universal Gateway | 4.5.0 < 4.5.0.48 | affected |
| WSO2 | WSO2 Universal Gateway | 4.6.0 < 4.6.0.12 | affected |
| WSO2 | WSO2 Traffic Manager | 4.5.0 < 4.5.0.47 | affected |
| WSO2 | WSO2 Traffic Manager | 4.6.0 < 4.6.0.12 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Common Functions | 9.0.174 < 9.0.174.550 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Common Functions | 9.28.116 < 9.28.116.404 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Common Functions | 9.29.120 < 9.29.120.221 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Common Functions | 9.30.67 < 9.30.67.146 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Common Functions | 9.31.86 < 9.31.86.130 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Common Functions | 9.32.147 < 9.32.147.26 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Common Functions | 9.33.27 <= * | unaffected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.20.74 < 9.20.74.392 | affected |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.33.27 <= * | unaffected |
Weaknesses
- CWE-269: CWE-269: Improper Privilege Management
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.