Record summary

CVE-2026-1728 has a selected CVSS score of 9.8 (critical).

Description

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.5.0 to < 4.5.0.49affected
4.6.0 to < 4.6.0.13affected

Default status: unaffected

CVE ListBefore 4.0.0unknown
4.0.0 to < 4.0.0.384affected
4.1.0 to < 4.1.0.248affected
4.2.0 to < 4.2.0.188affected
4.3.0 to < 4.3.0.99affected
4.4.0 to < 4.4.0.63affected
4.5.0 to < 4.5.0.48affected
4.6.0 to < 4.6.0.12affected

WSO2 Carbon API Manager Rest API Common Functions

Browse WSO2 / WSO2 Carbon API Manager Rest API Common Functionsorg.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.common

Default status: unknown

CVE List9.0.174 to < 9.0.174.550affected
9.28.116 to < 9.28.116.404affected
9.29.120 to < 9.29.120.221affected
9.30.67 to < 9.30.67.146affected
9.31.86 to < 9.31.86.130affected
9.32.147 to < 9.32.147.26affected
9.33.27 to ≤ *unaffected

WSO2 Carbon API Manager Rest API Utility

Browse WSO2 / WSO2 Carbon API Manager Rest API Utilityorg.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util

Default status: unknown

CVE List9.20.74 to < 9.20.74.392affected
9.33.27 to ≤ *unaffected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.47affected
4.6.0 to < 4.6.0.12affected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.48affected
4.6.0 to < 4.6.0.12affected

References

2