← All CVEs

CVE-2025-9152

critical · 9.8

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.

9.8
CVSS
0.7%
EPSS (exploit prob.)
52nd
EPSS percentile
2025-10-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

Affected products

VendorProductAffected versions
wso2api_control_plane4.5.0
wso2api_manager3.2.0
wso2api_manager3.2.1
wso2api_manager4.0.0
wso2api_manager4.1.0
wso2api_manager4.2.0
wso2api_manager4.3.0
wso2api_manager4.4.0
wso2api_manager4.5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-9152