CVE-2025-8325 Details
Description
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments.
A vulnerability exists in WSO2 API Manager, WSO2 API Control Plane, WSO2 Traffic Manager, and WSO2 Universal Gateway, all in version 4.5.0, as well as WSO2 API Manager versions 4.4.0, 4.3.0, 4.2.0, 4.1.0, 4.0.0, 3.2.1, and 3.2.0. The issue arises from the software's failure to properly enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can access these APIs, bypassing necessary permission checks. This vulnerability also extends to Internal Service APIs, particularly in WSO2 API Manager 3.x versions, where such APIs may be externally accessible, exposing sensitive endpoints.
Users can apply the relevant fixes available on the WSO2 GitHub repository. For those with a WSO2 Support Subscription, updates can be obtained through the WSO2 Updates service.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4401/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-281 | Improper Preservation of Permissions | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 api control plane | >= 4.5.0, < 4.5.0.18 |
CPE
Remediation
| |
| wso2 api manager | >= 3.2.0, < 3.2.0.435 >= 3.2.1, < 3.2.1.55 >= 4.0.0, < 4.0.0.355 >= 4.1.0, < 4.1.0.219 >= 4.2.0, < 4.2.0.157 >= 4.3.0, < 4.3.0.70 >= 4.4.0, < 4.4.0.33 >= 4.5.0, < 4.5.0.17 |
CPE
Remediation
| |
| wso2 traffic manager | >= 4.5.0, < 4.5.0.17 |
CPE
Remediation
| |
| wso2 universal gateway | >= 4.5.0, < 4.5.0.17 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | New CVE Received | WSO2 LLC |