← All CVEs

CVE-2025-10611

critical · 9.8

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.

9.8
CVSS
0.8%
EPSS (exploit prob.)
56th
EPSS percentile
2025-10-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-863

Affected products

VendorProductAffected versions
wso2api_control_plane4.5.0
wso2api_manager2.1.0
wso2api_manager2.2.0
wso2api_manager2.5.0
wso2api_manager2.6.0
wso2api_manager3.0.0
wso2api_manager3.1.0
wso2api_manager3.2.0
wso2api_manager3.2.1
wso2api_manager4.0.0
wso2api_manager4.1.0
wso2api_manager4.2.0
wso2api_manager4.3.0
wso2api_manager4.4.0
wso2api_manager4.5.0
wso2identity_server5.3.0
wso2identity_server5.5.0
wso2identity_server5.6.0
wso2identity_server5.7.0
wso2identity_server5.8.0
wso2identity_server5.9.0
wso2identity_server5.10.0
wso2identity_server5.11.0
wso2identity_server6.0.0
wso2identity_server6.1.0
wso2identity_server7.0.0
wso2identity_server7.1.0
wso2identity_server_as_key_manager5.3.0
wso2identity_server_as_key_manager5.5.0
wso2identity_server_as_key_manager5.6.0
wso2identity_server_as_key_manager5.7.0
wso2identity_server_as_key_manager5.9.0
wso2identity_server_as_key_manager5.10.0
wso2open_banking_am1.4.0
wso2open_banking_am1.5.0
wso2open_banking_am2.0.0
wso2open_banking_iam2.0.0
wso2open_banking_km1.4.0
wso2open_banking_km1.5.0
wso2traffic_manager4.5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-10611