Improper Access Control in WSO2 Products
CVE-2025-9804
8.9HIGH
Key Information:
- Vendor
Wso2
- Status
- Vendor
- CVE Published:
- 16 October 2025
What is CVE-2025-9804?
An improper access control vulnerability exists in multiple WSO2 products due to inadequate permission enforcement in specific internal SOAP Admin Services and System REST APIs. This vulnerability allows a low-privileged user to potentially perform unauthorized operations, including the retrieval of sensitive server-level information. Note that the APIs exposed through the WSO2 API Manager's API Gateway are not impacted by this flaw, emphasizing the need for vigilant management of internal administrative interfaces.
Affected Version(s)
API Manager Analytics 2.0.0 < 2.0.0.14
API Manager Analytics 2.1.0 < 2.1.0.19
API Manager Analytics 2.2.0 < 2.2.0.30