← CVE Tracker
9.6CRITICAL
CVE-2025-9804 — An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission…
Wso2 · Api Control Plane · Published 16 Oct 2025 · Modified 26 Sept 2026
Wso2 · Api Control Plane · Published 16 Oct 2025 · Modified 26 Sept 2026
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
Link: adminadda.com/cve/CVE-2025-9804