Insufficient Token Restrictions in WSO2 Products Allow Low-privileged User Access
CVE-2026-1728

9.8CRITICAL

What is CVE-2026-1728?

This vulnerability affects WSO2 products by failing to adequately restrict tokens issued to low-privileged users. This oversight enables these users to exploit Admin REST APIs, potentially compromising system integrity and leading to a complete takeover of administrative functions. Attackers would need to already possess a low-privileged account and have access to a valid token, which presents a significant risk to organizations relying on secure API management and administrative controls.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.49

WSO2 API Control Plane 4.6.0 < 4.6.0.13

WSO2 API Manager 4.0.0 < 4.0.0.384

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.