CVE-2025-9804 is an improper access control vulnerability affecting multiple WSO2 products, allowing a low-privileged user to perform unauthorized operations and access server-level information through internal SOAP Admin Services and System REST APIs. This vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity and requires only low privileges, primarily impacting confidentiality. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion, with one mention linking it to authentication bypasses in WSO2 products.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.5.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:2.0.0:*:*:*:*:*:*:* | ||
2.1.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:2.1.0:*:*:*:*:*:*:* | ||
2.2.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:2.2.0:*:*:*:*:*:*:* | ||
2.5.0CPE matchmatch criteria | cpe:2.3:a:wso2:api_manager:2.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.