WSO2 API Manager Improper Privilege Management in DCR Endpoint
CVE-2025-9152 Published on October 16, 2025
Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint.
A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Vulnerability Analysis
CVE-2025-9152 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2025-9152
Want to know whenever a new CVE is published for Wso2 Api Manager? stack.watch will email you.
Affected Versions
WSO2 API Manager:- Before 3.2.0 is unknown.
- Version 3.2.0 and below 3.2.0.437 is affected.
- Version 3.2.1 and below 3.2.1.57 is affected.
- Version 4.0.0 and below 4.0.0.357 is affected.
- Version 4.1.0 and below 4.1.0.221 is affected.
- Version 4.2.0 and below 4.2.0.159 is affected.
- Version 4.3.0 and below 4.3.0.72 is affected.
- Version 4.4.0 and below 4.4.0.35 is affected.
- Version 4.5.0 and below 4.5.0.19 is affected.
- Version 4.5.0 and below 4.5.0.20 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.