WSO2 Event Processor RCE via Siddhi Exec Plan Injection
CVE-2025-5717 Published on September 23, 2025
Authenticated Remote Code Execution in Multiple WSO2 Products via Event Processor Admin Service
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server.
Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.
Vulnerability Analysis
Weakness Type
What is a Code Injection Vulnerability?
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVE-2025-5717 has been classified to as a Code Injection vulnerability or weakness.
Products Associated with CVE-2025-5717
Want to know whenever a new CVE is published for Wso2 Api Manager? stack.watch will email you.
Affected Versions
WSO2 API Manager:- Before 3.0.0 is unknown.
- Version 3.0.0 and below 3.0.0.174 is affected.
- Version 3.1.0 and below 3.1.0.330 is affected.
- Version 3.2.0 and below 3.2.0.426 is affected.
- Version 3.2.1 and below 3.2.1.46 is affected.
- Version 4.0.0 and below 4.0.0.344 is affected.
- Version 4.1.0 and below 4.1.0.208 is affected.
- Version 4.2.0 and below 4.2.0.147 is affected.
- Version 4.3.0 and below 4.3.0.59 is affected.
- Version 4.4.0 and below 4.4.0.22 is affected.
- Version 4.5.0 and below 4.5.0.6 is affected.
- Before 2.0.0 is unknown.
- Version 2.0.0 and below 2.0.0.379 is affected.
- Version 4.5.0 and below 4.5.0.6 is affected.
- Version 4.5.0 and below 4.5.0.6 is affected.
- Version 3.2.6 and below 3.2.6.8 is affected.
- Version 3.2.7 and below 3.2.7.6 is affected.
- Version 3.2.8 and below 3.2.8.3 is affected.
- Version 3.2.10 and below 3.2.10.1 is affected.
- Version 3.2.13 and below 3.2.13.2 is affected.
- Version 3.2.14 and below 3.2.14.1 is affected.
- Version 3.2.15, <= * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.