CVE-2026-1728

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-06 08:16

Updated : 2026-08-10 12:32


NVD link : CVE-2026-1728

Mitre link : CVE-2026-1728

CVE.ORG link : CVE-2026-1728


JSON object : View

Products Affected

wso2

  • api_control_plane
  • traffic_manager
  • api_manager
  • universal_gateway
CWE
CWE-269

Improper Privilege Management