WSO2 Internal Admin API Improper Access Control
CVE-2025-9804 Published on October 16, 2025

Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2025-9804 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2025-9804

Want to know whenever a new CVE is published for Wso2 products? stack.watch will email you.

 
 
 
 
 
 
 

Affected Versions

WSO2 Identity Server as Key Manager: WSO2 Identity Server: WSO2 Open Banking KM: WSO2 Open Banking IAM: WSO2 Open Banking AM: WSO2 API Manager: WSO2 Identity Server Analytics: WSO2 API Manager Analytics: WSO2 Enterprise Integrator: WSO2 Enterprise Service Bus Analytics: WSO2 Data Analytics Server: WSO2 Enterprise Mobility Manager: WSO2 Universal Gateway: WSO2 API Control Plane: WSO2 Traffic Manager: org.wso2.carbon.extension.identity.authenticator.outbound.totp:org.wso2.carbon.extension.identity.authenticator.totp.connector: org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util: org.wso2.carbon:org.wso2.carbon.base: org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.mgt: org.wso2.carbon:org.wso2.carbon.server.admin: org.wso2.carbon.identity.workflow.user:org.wso2.carbon.user.mgt.workflow:

Exploit Probability

EPSS
0.03%
Percentile
9.74%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.