CVE-2026-1728
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
Record summary
CVE-2026-1728 has a selected CVSS score of 9.8 (critical).
Description
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
WSO2 API Control PlaneBrowse WSO2 / WSO2 API Control PlaneDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.49 | affected |
| 4.6.0 to < 4.6.0.13 | affected | ||
WSO2 API ManagerBrowse WSO2 / WSO2 API ManagerDefault status: unaffected | CVE List | Before 4.0.0 | unknown |
| 4.0.0 to < 4.0.0.384 | affected | ||
| 4.1.0 to < 4.1.0.248 | affected | ||
| 4.2.0 to < 4.2.0.188 | affected | ||
| 4.3.0 to < 4.3.0.99 | affected | ||
| 4.4.0 to < 4.4.0.63 | affected | ||
| 4.5.0 to < 4.5.0.48 | affected | ||
| 4.6.0 to < 4.6.0.12 | affected | ||
WSO2 Carbon API Manager Rest API Common FunctionsBrowse WSO2 / WSO2 Carbon API Manager Rest API Common Functionsorg.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.commonDefault status: unknown | CVE List | 9.0.174 to < 9.0.174.550 | affected |
| 9.28.116 to < 9.28.116.404 | affected | ||
| 9.29.120 to < 9.29.120.221 | affected | ||
| 9.30.67 to < 9.30.67.146 | affected | ||
| 9.31.86 to < 9.31.86.130 | affected | ||
| 9.32.147 to < 9.32.147.26 | affected | ||
| 9.33.27 to ≤ * | unaffected | ||
WSO2 Carbon API Manager Rest API UtilityBrowse WSO2 / WSO2 Carbon API Manager Rest API Utilityorg.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.utilDefault status: unknown | CVE List | 9.20.74 to < 9.20.74.392 | affected |
| 9.33.27 to ≤ * | unaffected | ||
WSO2 Traffic ManagerBrowse WSO2 / WSO2 Traffic ManagerDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.47 | affected |
| 4.6.0 to < 4.6.0.12 | affected | ||
WSO2 Universal GatewayBrowse WSO2 / WSO2 Universal GatewayDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.48 | affected |
| 4.6.0 to < 4.6.0.12 | affected |