CVE-2025-9312 Details
Description
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the affected components may permit unauthenticated requests even when mTLS is enabled. This condition occurs when relying on the default mTLS settings for System REST APIs or when the mTLS authenticator is enabled for SOAP services, causing these interfaces to accept requests without enforcing additional authentication. Successful exploitation allows a malicious actor with network access to the affected endpoints to gain administrative privileges and perform unauthorized operations. The vulnerability is exploitable only when the impacted mTLS flows are enabled and accessible in a given deployment. Other certificate-based authentication mechanisms such as Mutual TLS OAuth client authentication and X.509 login flows are not affected, and APIs served through the API Gateway of WSO2 API Manager remain unaffected.
A vulnerability allowing missing authentication enforcement has been identified in the mutual TLS (mTLS) implementation of several WSO2 products. This issue arises in the System REST APIs and SOAP services due to improper validation of client certificate-based authentication in certain default configurations. As a result, these components may accept unauthenticated requests even when mTLS is enabled. This vulnerability occurs when the default mTLS settings for System REST APIs are used or when the mTLS authenticator is activated for SOAP services, leading these interfaces to allow requests without additional authentication. Exploitation of this vulnerability enables a malicious actor with network access to the affected endpoints to obtain administrative privileges and execute unauthorized actions. The issue is only exploitable when the impacted mTLS flows are enabled and accessible in the deployment. Other certificate-based authentication methods, such as Mutual TLS OAuth client authentication and X.509 login flows, are not affected. Additionally, APIs served through the WSO2 API Manager's API Gateway are not impacted.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4494/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 api control plane | 4.5.0 - |
CPE
Remediation
| |
| wso2 api manager | 2.2.0 2.5.0 2.6.0 3.0.0 3.1.0 3.2.0 3.2.1 4.0.0 4.1.0 - 4.2.0 - 4.3.0 - 4.4.0 - 4.5.0 - |
CPE
Remediation
| |
| wso2 identity server | 5.2.0 5.3.0 5.4.0 5.4.1 5.5.0 5.6.0 5.7.0 5.8.0 5.9.0 5.10.0 5.11.0 6.0.0 - 6.1.0 - 7.0.0 - 7.1.0 - 7.2.0 |
CPE
Remediation
| |
| wso2 identity server as key manager | 5.3.0 5.5.0 5.6.0 5.7.0 5.9.0 5.10.0 |
CPE
Remediation
| |
| wso2 open banking am | 1.4.0 1.5.0 2.0.0 |
CPE
Remediation
| |
| wso2 open banking iam | 2.0.0 |
CPE
Remediation
| |
| wso2 open banking km | 1.4.0 1.5.0 |
CPE
Remediation
| |
| wso2 traffic manager | 4.5.0 |
CPE
Remediation
| |
| wso2 universal gateway | 4.5.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 8, 2025 | Initial Analysis | [email protected] |
| Nov 18, 2025 | New CVE Received | WSO2 LLC |