Record summary

CVE-2025-10611 has a selected CVSS score of 9.8 (critical).

Description

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2025 · Source: CVE List

Affected products and versions

11
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.5.0 to < 4.5.0.29affected

Default status: unaffected

CVE ListBefore 2.1.0unknown
2.1.0 to < 2.1.0.42affected
2.2.0 to < 2.2.0.61affected
2.5.0 to < 2.5.0.87affected
2.6.0 to < 2.6.0.148affected
3.0.0 to < 3.0.0.178affected
3.1.0 to < 3.1.0.345affected
3.2.0 to < 3.2.0.446affected
3.2.1 to < 3.2.1.66affected
4.0.0 to < 4.0.0.366affected
4.1.0 to < 4.1.0.228affected
4.2.0 to < 4.2.0.169affected
Showing 12 of 15 version ranges

Default status: unaffected

CVE ListBefore 5.3.0unknown
5.3.0 to < 5.3.0.39affected
5.5.0 to < 5.5.0.54affected
5.6.0 to < 5.6.0.62affected
5.7.0 to < 5.7.0.128affected
5.8.0 to < 5.8.0.112affected
5.9.0 to < 5.9.0.171affected
5.10.0 to < 5.10.0.375affected
5.11.0 to < 5.11.0.419affected
6.0.0 to < 6.0.0.248affected
6.1.0 to < 6.1.0.248affected
7.0.0 to < 7.0.0.124affected
Showing 12 of 13 version ranges

WSO2 Identity Server as Key Manager

Browse WSO2 / WSO2 Identity Server as Key Manager

Default status: unaffected

CVE ListBefore 5.3.0unknown
5.3.0 to < 5.3.0.44affected
5.5.0 to < 5.5.0.55affected
5.6.0 to < 5.6.0.77affected
5.7.0 to < 5.7.0.127affected
5.9.0 to < 5.9.0.178affected
5.10.0 to < 5.10.0.365affected

Default status: unaffected

CVE ListBefore 1.4.0unknown
1.4.0 to < 1.4.0.141affected
1.5.0 to < 1.5.0.142affected
2.0.0 to < 2.0.0.394affected

Default status: unaffected

CVE ListBefore 2.0.0unknown
2.0.0 to < 2.0.0.414affected

Default status: unaffected

CVE ListBefore 1.4.0unknown
1.4.0 to < 1.4.0.135affected
1.5.0 to < 1.5.0.125affected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.27affected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.27affected

org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.service

Browse WSO2 / org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.service

Default status: unknown

CVE List1.1.1 to < 1.1.1.7affected
1.1.16 to < 1.1.16.6affected
1.1.18 to < 1.1.18.7affected
1.1.20 to < 1.1.20.9affected
1.1.26 to < 1.1.26.11affected
1.3.6 to < 1.3.6.11affected
1.4.0 to < 1.4.0.21affected
1.4.25 to < 1.4.25.27affected
1.4.52 to < 1.4.52.6affected
1.6.1 to < 1.6.1.12affected
1.7.1 to < 1.7.1.7affected
1.8.11 to < 1.8.11.8affected
Showing 12 of 17 version ranges

org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.valve

Browse WSO2 / org.wso2.carbon.identity.auth.rest:org.wso2.carbon.identity.auth.valve

Default status: unknown

CVE List1.1.1 to < 1.1.1.7affected
1.1.16 to < 1.1.16.6affected
1.1.18 to < 1.1.18.7affected
1.1.20 to < 1.1.20.9affected
1.1.26 to < 1.1.26.11affected
1.3.6 to < 1.3.6.11affected
1.4.0 to < 1.4.0.21affected
1.4.25 to < 1.4.25.27affected
1.4.52 to < 1.4.52.6affected
1.6.1 to < 1.6.1.12affected
1.7.1 to < 1.7.1.7affected
1.8.11 to < 1.8.11.8affected
Showing 12 of 17 version ranges

References

2