CVE-2025-10611

CRITICAL

WSO2 API Control Plane and API Manager - Incorrect Authorization via REST API Bypass

Title source: llm
STIX 2.1

Description

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0078
EPSS Percentile 51.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (41)
wso2/api_control_plane 4.5.0
wso2/api_manager 2.1.0
wso2/api_manager 2.2.0
wso2/api_manager 2.5.0
wso2/api_manager 2.6.0
wso2/api_manager 3.0.0
wso2/api_manager 3.1.0
wso2/api_manager 3.2.0
wso2/api_manager 3.2.1
wso2/api_manager 4.0.0
... and 31 more
Published Oct 16, 2025
Tracked Since Feb 18, 2026