Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
Summary
| CVE | CVE-2026-1728 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:31 UTC |
| Updated | 2026-08-06 15:31:57 UTC |
| Description | Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.002970000 probability, percentile 0.219090000 (date 2026-08-08)
Problem Types: CWE-269 | CWE-269 CWE-269: Improper Privilege Management
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 API Manager | unknown 4.0.0 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.0.0 4.0.0.384 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.1.0 4.1.0.248 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.2.0 4.2.0.188 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.3.0 4.3.0.99 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.4.0 4.4.0.63 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.5.0 4.5.0.48 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.6.0 4.6.0.12 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.5.0 4.5.0.49 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.6.0 4.6.0.13 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.5.0 4.5.0.48 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.6.0 4.6.0.12 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.5.0 4.5.0.47 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.6.0 4.6.0.12 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Common Functions | affected 9.0.174 9.0.174.550 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Common Functions | affected 9.28.116 9.28.116.404 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Common Functions | affected 9.29.120 9.29.120.221 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Common Functions | affected 9.30.67 9.30.67.146 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Common Functions | affected 9.31.86 9.31.86.130 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Common Functions | affected 9.32.147 9.32.147.26 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Common Functions | unaffected 9.33.27 * custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | affected 9.20.74 9.20.74.392 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | unaffected 9.33.27 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5077/#solution
There are currently no legacy QID mappings associated with this CVE.