Authentication Bypass in WSO2 Management Console
CVE-2025-5605
4.3MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 24 October 2025
What is CVE-2025-5605?
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. This issue allows an unauthorized actor to manipulate request URIs, circumventing authentication processes and gaining access to restricted resources. While full account compromise is not possible, this vulnerability does enable access to sensitive internal information, such as memory statistics, which could pose risks to system integrity.
Affected Version(s)
org.wso2.carbon:org.wso2.carbon.ui 4.5.3 < 4.5.3.40
org.wso2.carbon:org.wso2.carbon.ui 4.6.0 < 4.6.0.1224
org.wso2.carbon:org.wso2.carbon.ui 4.6.1 < 4.6.1.150
