CVE-2025-9312 is a critical missing authentication enforcement vulnerability in the mutual TLS (mTLS) implementation of System REST APIs and SOAP services across multiple WSO2 products, including API Manager and Identity Server. This flaw allows unauthenticated requests to be accepted even when mTLS is enabled, due to improper validation of client certificates in certain default configurations. With a CVSS score of 9.8 (Critical), successful exploitation grants administrative privileges and enables unauthorized operations by any malicious actor with network access to the affected endpoints. While the vulnerability is exploitable only when specific mTLS flows are enabled, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.5.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:* | ||
2.2.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:2.2.0:*:*:*:*:*:*:* | ||
2.5.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:2.5.0:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:2.6.0:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.