Improper Access Control in WSO2 Products
CVE-2025-9804
Key Information:
- Vendor
Wso2
- Status
- Vendor
- CVE Published:
- 16 October 2025
What is CVE-2025-9804?
An improper access control vulnerability exists in multiple WSO2 products due to inadequate permission enforcement in specific internal SOAP Admin Services and System REST APIs. This vulnerability allows a low-privileged user to potentially perform unauthorized operations, including the retrieval of sensitive server-level information. Note that the APIs exposed through the WSO2 API Manager's API Gateway are not impacted by this flaw, emphasizing the need for vigilant management of internal administrative interfaces.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
API Manager Analytics 2.0.0 < 2.0.0.14
API Manager Analytics 2.1.0 < 2.1.0.19
API Manager Analytics 2.2.0 < 2.2.0.30
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
