CVE-2026-1728
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
| CWE | CWE-269 |
| Vendor | wso2 |
| Product | wso2 api manager |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for wso2 wso2 api manager
Be the first to know when new critical vulnerabilities affecting wso2 wso2 api manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
WSO2 / WSO2 API Manager
4.0.0 < 4.0.0.384 4.1.0 < 4.1.0.248 4.2.0 < 4.2.0.188 4.3.0 < 4.3.0.99 4.4.0 < 4.4.0.63 4.5.0 < 4.5.0.48 4.6.0 < 4.6.0.12
WSO2 / WSO2 API Control Plane
4.5.0 < 4.5.0.49 4.6.0 < 4.6.0.13
WSO2 / WSO2 Universal Gateway
4.5.0 < 4.5.0.48 4.6.0 < 4.6.0.12
WSO2 / WSO2 Traffic Manager
4.5.0 < 4.5.0.47 4.6.0 < 4.6.0.12
WSO2 / WSO2 Carbon API Manager Rest API Common Functions
9.0.174 < 9.0.174.550 9.28.116 < 9.28.116.404 9.29.120 < 9.29.120.221 9.30.67 < 9.30.67.146 9.31.86 < 9.31.86.130 9.32.147 < 9.32.147.26
WSO2 / WSO2 Carbon API Manager Rest API Utility
9.20.74 < 9.20.74.392