← Back

CVE-2025-11093

nvd nist
Published: Nov 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integration runtime environment. By default, access to these scripting engines is limited to administrators in WSO2 Micro Integrator and WSO2 Enterprise Integrator, while in WSO2 API Manager, access extends to both administrators and API creators. This may allow trusted-but-privileged users to perform unauthorized actions or compromise the execution environment.

Affected (17)

6 products
Api Control Plane
Api Manager
Enterprise Integrator
Micro Integrator
Traffic Manager
Universal Gateway
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
From 4.5.0 to 4.5.0.29
Wso2
From 3.1.0 to 3.1.0.345
From 3.2.0 to 3.2.0.446
From 3.2.1 to 3.2.1.66
From 4.1.0 to 4.1.0.228
From 4.2.0 to 4.2.0.169
From 4.3.0 to 4.3.0.81
From 4.4.0 to 4.4.0.45
From 4.5.0 to 4.5.0.28
From 6.6.0 to 6.6.0.224
Wso2
From 4.0.0 to 4.0.0.145
From 4.1.0 to 4.1.0.147
From 4.2.0 to 4.2.0.141
From 4.3.0 to 4.3.0.42
From 4.4.0 to 4.4.0.27
From 4.5.0 to 4.5.0.27
From 4.5.0 to 4.5.0.27

References (1)

Timeline

No history available yet.