← Back

CVE-2024-7096

nvd nist
Published: May 30, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible to the attacker. * The deployment includes an internally used attribute that is not part of the default WSO2 product configuration. * At least one custom role exists with non-default permissions. * The attacker has knowledge of the custom role and the internal attribute used in the deployment. Exploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms.

Affected (41)

6 products
Api Manager
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Open Banking Km
Configuration A
41 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
Version 2.0.0
Version 2.1.0
Version 2.2.0
Version 2.5.0
Version 2.6.0
Version 3.0.0
Version 3.1.0
Version 3.2.0
Version 3.2.1
Version 4.0.0
Version 4.1.0
Version 4.2.0
Version 4.3.0
Wso2
Version 5.10.0
Version 5.11.0
Version 5.2.0
Version 5.3.0
Version 5.4.0
Version 5.4.1
Version 5.5.0
Version 5.6.0
Version 5.7.0
Version 5.8.0
Version 5.9.0
Version 6.0.0
Version 6.1.0
Version 7.0.0
Wso2
Version 5.10.0
Version 5.3.0
Version 5.5.0
Version 5.6.0
Version 5.7.0
Version 5.9.0
Wso2
Version 1.3.0
Version 1.4.0
Version 1.5.0
Version 2.0.0
Version 2.0.0
Wso2
Version 1.3.0
Version 1.4.0
Version 1.5.0

References (1)

Timeline

No history available yet.