Insufficient Token Restrictions in WSO2 Products Allow Low-privileged User Access
CVE-2026-1728
9.8CRITICAL
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2026-1728?
This vulnerability affects WSO2 products by failing to adequately restrict tokens issued to low-privileged users. This oversight enables these users to exploit Admin REST APIs, potentially compromising system integrity and leading to a complete takeover of administrative functions. Attackers would need to already possess a low-privileged account and have access to a valid token, which presents a significant risk to organizations relying on secure API management and administrative controls.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.49
WSO2 API Control Plane 4.6.0 < 4.6.0.13
WSO2 API Manager 4.0.0 < 4.0.0.384
