CVE-2025-9152 Details
Description
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
A vulnerability allowing improper privilege management has been identified in WSO2 API Manager versions 4.5.0, 4.4.0, 4.3.0, 4.2.0, 4.1.0, 4.0.0, 3.2.1, and 3.2.0. This vulnerability arises from inadequate authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. As a result, malicious users can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Users of WSO2 API Manager can update to version 4.5.0, 4.4.0, 4.3.0, 4.2.0, 4.1.0, 4.0.0, 3.2.1, or 3.2.0. Community users can apply the public fix available on GitHub. WSO2 Support Subscription Holders can use WSO2 Updates to apply the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| wso2 api control plane | 4.5.0 - |
CPE
Remediation
| |
| wso2 api manager | 3.2.0 3.2.1 4.0.0 4.1.0 - 4.2.0 - 4.3.0 - 4.4.0 - 4.5.0 - |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | Initial Analysis | [email protected] |
| Oct 17, 2025 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | New CVE Received | WSO2 LLC |