Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-1728

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-269 Gestión de privilegios incorrecta
Fecha de publicación:
06/08/2026
Última modificación:
10/08/2026

Descripción

*** Pendiente de traducción *** Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.<br /> <br /> Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* 4.5.0 (incluyendo) 4.5.0.49 (excluyendo)
cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* 4.6.0 (incluyendo) 4.6.0.13 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.0.0 (incluyendo) 4.0.0.384 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.1.0 (incluyendo) 4.1.0.248 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.2.0 (incluyendo) 4.2.0.188 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.3.0 (incluyendo) 4.3.0.99 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.4.0 (incluyendo) 4.4.0.63 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.5.0 (incluyendo) 4.5.0.48 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.6.0 (incluyendo) 4.6.0.12 (excluyendo)
cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* 4.5.0 (incluyendo) 4.5.0.47 (excluyendo)
cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* 4.6.0 (incluyendo) 4.6.0.12 (excluyendo)
cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* 4.5.0 (incluyendo) 4.5.0.48 (excluyendo)
cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* 4.6.0 (incluyendo) 4.6.0.12 (excluyendo)