CVE-2026-1728
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
06/08/2026
Last modified:
10/08/2026
Description
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.<br />
<br />
Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* | 4.5.0 (including) | 4.5.0.49 (excluding) |
| cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* | 4.6.0 (including) | 4.6.0.13 (excluding) |
| cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | 4.0.0 (including) | 4.0.0.384 (excluding) |
| cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | 4.1.0 (including) | 4.1.0.248 (excluding) |
| cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | 4.2.0 (including) | 4.2.0.188 (excluding) |
| cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | 4.3.0 (including) | 4.3.0.99 (excluding) |
| cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | 4.4.0 (including) | 4.4.0.63 (excluding) |
| cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | 4.5.0 (including) | 4.5.0.48 (excluding) |
| cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* | 4.6.0 (including) | 4.6.0.12 (excluding) |
| cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* | 4.5.0 (including) | 4.5.0.47 (excluding) |
| cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* | 4.6.0 (including) | 4.6.0.12 (excluding) |
| cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* | 4.5.0 (including) | 4.5.0.48 (excluding) |
| cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* | 4.6.0 (including) | 4.6.0.12 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



