← Back

CVE-2025-10611

nvd nist
Published: Oct 16, 2025Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.

Affected (41)

9 products
Api Control Plane
Api Manager
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Open Banking Km
Traffic Manager
Universal Gateway
Configuration A
41 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.5.0
Wso2
Version 2.1.0
Version 2.2.0
Version 2.5.0
Version 2.6.0
Version 3.0.0
Version 3.1.0
Version 3.2.0
Version 3.2.1
Version 4.0.0
Version 4.1.0
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Wso2
Version 5.10.0
Version 5.11.0
Version 5.3.0
Version 5.5.0
Version 5.6.0
Version 5.7.0
Version 5.8.0
Version 5.9.0
Version 6.0.0
Version 6.1.0
Version 7.0.0
Version 7.1.0
Wso2
Version 5.10.0
Version 5.3.0
Version 5.5.0
Version 5.6.0
Version 5.7.0
Version 5.9.0
Wso2
Version 1.4.0
Version 1.5.0
Version 2.0.0
Version 2.0.0
Wso2
Version 1.4.0
Version 1.5.0
Version 4.5.0
Version 4.5.0

References (1)

Timeline

No history available yet.