Back to overview

CVE-2025-10611

CRITICAL
9.8
CVSS 3.1
Description
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.

Metadata

CVE ID
CVE-2025-10611
State
PUBLISHED
Assigner
WSO2
Reserved
2025-09-17 08:56 UTC
Published
2025-10-16 12:09 UTC
Last updated
2025-10-16 13:34 UTC
Primary CWE
CWE-863
CWE-863 Incorrect Authorization
Vendor / Product
WSO2 / WSO2 API Manager
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (11)
VendorProductPlatformVersions
WSO2 org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.service 1.1.1 < 1.1.1.7, 1.1.16 < 1.1.16.6, 1.1.18 < 1.1.18.7, 1.1.20 < 1.1.20.9 …
WSO2 org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.valve 1.1.1 < 1.1.1.7, 1.1.16 < 1.1.16.6, 1.1.18 < 1.1.18.7, 1.1.20 < 1.1.20.9 …
WSO2 WSO2 API Control Plane 4.5.0 < 4.5.0.29
WSO2 WSO2 API Manager 0 < 2.1.0, 2.1.0 < 2.1.0.42, 2.2.0 < 2.2.0.61, 2.5.0 < 2.5.0.87 …
WSO2 WSO2 Identity Server 0 < 5.3.0, 5.3.0 < 5.3.0.39, 5.5.0 < 5.5.0.54, 5.6.0 < 5.6.0.62 …
WSO2 WSO2 Identity Server as Key Manager 0 < 5.3.0, 5.3.0 < 5.3.0.44, 5.5.0 < 5.5.0.55, 5.6.0 < 5.6.0.77 …
WSO2 WSO2 Open Banking AM 0 < 1.4.0, 1.4.0 < 1.4.0.141, 1.5.0 < 1.5.0.142, 2.0.0 < 2.0.0.394
WSO2 WSO2 Open Banking IAM 0 < 2.0.0, 2.0.0 < 2.0.0.414
WSO2 WSO2 Open Banking KM 0 < 1.4.0, 1.4.0 < 1.4.0.135, 1.5.0 < 1.5.0.125
WSO2 WSO2 Traffic Manager 4.5.0 < 4.5.0.27
WSO2 WSO2 Universal Gateway 4.5.0 < 4.5.0.27
Weakness (CWE)
CWESourceDescription
CWE-863 adp CWE-863 Incorrect Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview