← Back

CVE-2026-1728

nvd nist
Published: Aug 6, 2026Modified: Aug 10, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

Affected (13)

4 products
Api Control Plane
Api Manager
Traffic Manager
Universal Gateway
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.49
From 4.6.0 to 4.6.0.13
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.0.0 to 4.0.0.384
From 4.1.0 to 4.1.0.248
From 4.2.0 to 4.2.0.188
From 4.3.0 to 4.3.0.99
From 4.4.0 to 4.4.0.63
From 4.5.0 to 4.5.0.48
From 4.6.0 to 4.6.0.12
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.47
From 4.6.0 to 4.6.0.12
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.48
From 4.6.0 to 4.6.0.12

References (1)

Timeline

No history available yet.