CVE-2026-1728
EUVD-2026-5382106.08.2026, 08:16
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wso2 | api_control_plane | 4.5.0 ≤ 𝑥 < 4.5.0.49 |
| wso2 | api_control_plane | 4.6.0 ≤ 𝑥 < 4.6.0.13 |
| wso2 | api_manager | 4.0.0 ≤ 𝑥 < 4.0.0.384 |
| wso2 | api_manager | 4.1.0 ≤ 𝑥 < 4.1.0.248 |
| wso2 | api_manager | 4.2.0 ≤ 𝑥 < 4.2.0.188 |
| wso2 | api_manager | 4.3.0 ≤ 𝑥 < 4.3.0.99 |
| wso2 | api_manager | 4.4.0 ≤ 𝑥 < 4.4.0.63 |
| wso2 | api_manager | 4.5.0 ≤ 𝑥 < 4.5.0.48 |
| wso2 | api_manager | 4.6.0 ≤ 𝑥 < 4.6.0.12 |
| wso2 | traffic_manager | 4.5.0 ≤ 𝑥 < 4.5.0.47 |
| wso2 | traffic_manager | 4.6.0 ≤ 𝑥 < 4.6.0.12 |
| wso2 | universal_gateway | 4.5.0 ≤ 𝑥 < 4.5.0.48 |
| wso2 | universal_gateway | 4.6.0 ≤ 𝑥 < 4.6.0.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration