Authentication Bypass in WSO2 Management Console
CVE-2025-5605
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 24 October 2025
What is CVE-2025-5605?
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. This issue allows an unauthorized actor to manipulate request URIs, circumventing authentication processes and gaining access to restricted resources. While full account compromise is not possible, this vulnerability does enable access to sensitive internal information, such as memory statistics, which could pose risks to system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
org.wso2.carbon:org.wso2.carbon.ui 4.5.3 < 4.5.3.40
org.wso2.carbon:org.wso2.carbon.ui 4.6.0 < 4.6.0.1224
org.wso2.carbon:org.wso2.carbon.ui 4.6.1 < 4.6.1.150
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
