CVE-2025-10611
Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
Record summary
CVE-2025-10611 has a selected CVSS score of 9.8 (critical).
Description
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2025 · Source: CVE List
Affected products and versions
11| Product | Source | Version range | Status |
|---|---|---|---|
WSO2 API Control PlaneBrowse WSO2 / WSO2 API Control PlaneDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.29 | affected |
WSO2 API ManagerBrowse WSO2 / WSO2 API ManagerDefault status: unaffected | CVE List | Before 2.1.0 | unknown |
| 2.1.0 to < 2.1.0.42 | affected | ||
| 2.2.0 to < 2.2.0.61 | affected | ||
| 2.5.0 to < 2.5.0.87 | affected | ||
| 2.6.0 to < 2.6.0.148 | affected | ||
| 3.0.0 to < 3.0.0.178 | affected | ||
| 3.1.0 to < 3.1.0.345 | affected | ||
| 3.2.0 to < 3.2.0.446 | affected | ||
| 3.2.1 to < 3.2.1.66 | affected | ||
| 4.0.0 to < 4.0.0.366 | affected | ||
| 4.1.0 to < 4.1.0.228 | affected | ||
| 4.2.0 to < 4.2.0.169 | affected | ||
| Showing 12 of 15 version ranges | |||
WSO2 Identity ServerBrowse WSO2 / WSO2 Identity ServerDefault status: unaffected | CVE List | Before 5.3.0 | unknown |
| 5.3.0 to < 5.3.0.39 | affected | ||
| 5.5.0 to < 5.5.0.54 | affected | ||
| 5.6.0 to < 5.6.0.62 | affected | ||
| 5.7.0 to < 5.7.0.128 | affected | ||
| 5.8.0 to < 5.8.0.112 | affected | ||
| 5.9.0 to < 5.9.0.171 | affected | ||
| 5.10.0 to < 5.10.0.375 | affected | ||
| 5.11.0 to < 5.11.0.419 | affected | ||
| 6.0.0 to < 6.0.0.248 | affected | ||
| 6.1.0 to < 6.1.0.248 | affected | ||
| 7.0.0 to < 7.0.0.124 | affected | ||
| Showing 12 of 13 version ranges | |||
WSO2 Identity Server as Key ManagerBrowse WSO2 / WSO2 Identity Server as Key ManagerDefault status: unaffected | CVE List | Before 5.3.0 | unknown |
| 5.3.0 to < 5.3.0.44 | affected | ||
| 5.5.0 to < 5.5.0.55 | affected | ||
| 5.6.0 to < 5.6.0.77 | affected | ||
| 5.7.0 to < 5.7.0.127 | affected | ||
| 5.9.0 to < 5.9.0.178 | affected | ||
| 5.10.0 to < 5.10.0.365 | affected | ||
WSO2 Open Banking AMBrowse WSO2 / WSO2 Open Banking AMDefault status: unaffected | CVE List | Before 1.4.0 | unknown |
| 1.4.0 to < 1.4.0.141 | affected | ||
| 1.5.0 to < 1.5.0.142 | affected | ||
| 2.0.0 to < 2.0.0.394 | affected | ||
WSO2 Open Banking IAMBrowse WSO2 / WSO2 Open Banking IAMDefault status: unaffected | CVE List | Before 2.0.0 | unknown |
| 2.0.0 to < 2.0.0.414 | affected | ||
WSO2 Open Banking KMBrowse WSO2 / WSO2 Open Banking KMDefault status: unaffected | CVE List | Before 1.4.0 | unknown |
| 1.4.0 to < 1.4.0.135 | affected | ||
| 1.5.0 to < 1.5.0.125 | affected | ||
WSO2 Traffic ManagerBrowse WSO2 / WSO2 Traffic ManagerDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.27 | affected |
WSO2 Universal GatewayBrowse WSO2 / WSO2 Universal GatewayDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.27 | affected |
org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.serviceBrowse WSO2 / org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.serviceDefault status: unknown | CVE List | 1.1.1 to < 1.1.1.7 | affected |
| 1.1.16 to < 1.1.16.6 | affected | ||
| 1.1.18 to < 1.1.18.7 | affected | ||
| 1.1.20 to < 1.1.20.9 | affected | ||
| 1.1.26 to < 1.1.26.11 | affected | ||
| 1.3.6 to < 1.3.6.11 | affected | ||
| 1.4.0 to < 1.4.0.21 | affected | ||
| 1.4.25 to < 1.4.25.27 | affected | ||
| 1.4.52 to < 1.4.52.6 | affected | ||
| 1.6.1 to < 1.6.1.12 | affected | ||
| 1.7.1 to < 1.7.1.7 | affected | ||
| 1.8.11 to < 1.8.11.8 | affected | ||
| Showing 12 of 17 version ranges | |||
org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.valveBrowse WSO2 / org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.valveDefault status: unknown | CVE List | 1.1.1 to < 1.1.1.7 | affected |
| 1.1.16 to < 1.1.16.6 | affected | ||
| 1.1.18 to < 1.1.18.7 | affected | ||
| 1.1.20 to < 1.1.20.9 | affected | ||
| 1.1.26 to < 1.1.26.11 | affected | ||
| 1.3.6 to < 1.3.6.11 | affected | ||
| 1.4.0 to < 1.4.0.21 | affected | ||
| 1.4.25 to < 1.4.25.27 | affected | ||
| 1.4.52 to < 1.4.52.6 | affected | ||
| 1.6.1 to < 1.6.1.12 | affected | ||
| 1.7.1 to < 1.7.1.7 | affected | ||
| 1.8.11 to < 1.8.11.8 | affected | ||
| Showing 12 of 17 version ranges | |||