CRITICAL🇵🇱 Wersja polska

CVE-2026-1728

CVSS 9.8v3.1pub. 2026-08-06upd. 2026-08-10

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Wso2 Api Control Plane

    APP
    Wso2
    4.5.0 – 4.5.0.49 (excl.)4.6.0 – 4.6.0.13 (excl.)
  • Wso2 Api Manager

    APP
    Wso2
    4.0.0 – 4.0.0.384 (excl.)4.1.0 – 4.1.0.248 (excl.)4.2.0 – 4.2.0.188 (excl.)4.3.0 – 4.3.0.99 (excl.)4.4.0 – 4.4.0.63 (excl.)4.5.0 – 4.5.0.48 (excl.)4.6.0 – 4.6.0.12 (excl.)
  • Wso2 Traffic Manager

    APP
    Wso2
    4.5.0 – 4.5.0.47 (excl.)4.6.0 – 4.6.0.12 (excl.)
  • Wso2 Universal Gateway

    APP
    Wso2
    4.5.0 – 4.5.0.48 (excl.)4.6.0 – 4.6.0.12 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-29464CRITICAL9.8⚠ KEVPL ✓same product

WSO2 — nieograniczony upload plików i RCE przez path traversal

CVE-2026-5430CRITICAL10.0PL ✓same product

Błąd weryfikacji algorytmu JWT umożliwia nieautoryzowany dostęp (WSO2)

CVE-2025-15039CRITICAL9.4PL ✓same product

Pominięcie uwierzytelniania wieloetapowego w WSO2 Conditional Authentication

CVE-2025-13590CRITICAL9.1PL ✓same product

WSO2 API Manager – RCE przez upload pliku z uprawnieniami administratora

CVE-2025-9312CRITICAL9.8PL ✓same product

Brak wymuszania uwierzytelniania mTLS w produktach WSO2 — nieautoryzowany dostęp administracyjny