CVE-2025-9804 Details
Description
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
A vulnerability allowing improper access control has been identified in multiple WSO2 products. This issue arises from inadequate permission enforcement in certain internal SOAP Admin Services and System REST APIs, allowing low-privileged users to perform unauthorized operations, such as accessing server-level information. The vulnerability is limited to internal administrative interfaces, with APIs exposed through the WSO2 API Manager's API Gateway remaining unaffected.
Users can apply the relevant fixes available on GitHub for their specific WSO2 product version. For WSO2 Support Subscription Holders, updates can be applied through the WSO2 Updates service.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4503/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| wso2 api control plane | 4.5.0 - |
CPE
Remediation
| |
| wso2 api manager | 2.0.0 2.1.0 2.2.0 2.5.0 2.6.0 3.0.0 3.1.0 3.2.0 3.2.1 4.0.0 4.1.0 - 4.2.0 - 4.3.0 - 4.4.0 - 4.5.0 - |
CPE
Remediation
| |
| wso2 api manager analytics | 2.0.0 2.1.0 2.2.0 2.5.0 |
CPE
Remediation
| |
| wso2 data analytics server | 3.1.0 3.2.0 |
CPE
Remediation
| |
| wso2 enterprise integrator | 6.2.0 6.3.0 |
CPE
Remediation
| |
| wso2 enterprise mobility manager | 2.2.0 |
CPE
Remediation
| |
| wso2 enterprise service bus | 5.0.0 |
CPE
Remediation
| |
| wso2 identity server | 5.2.0 5.3.0 5.4.0 5.4.1 5.5.0 5.6.0 5.7.0 5.8.0 5.9.0 5.10.0 5.11.0 6.0.0 - 6.1.0 - 7.0.0 - 7.1.0 - |
CPE
Remediation
| |
| wso2 identity server analytics | 5.2.0 5.3.0 5.5.0 5.6.0 |
CPE
Remediation
| |
| wso2 identity server as key manager | 5.3.0 5.5.0 5.6.0 5.7.0 5.9.0 5.10.0 |
CPE
Remediation
| |
| wso2 open banking am | 1.4.0 1.5.0 2.0.0 |
CPE
Remediation
| |
| wso2 open banking iam | 2.0.0 |
CPE
Remediation
| |
| wso2 open banking km | 1.4.0 1.5.0 |
CPE
Remediation
| |
| wso2 traffic manager | 4.5.0 |
CPE
Remediation
| |
| wso2 universal gateway | 4.5.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2025 | Initial Analysis | [email protected] |
| Oct 17, 2025 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | New CVE Received | WSO2 LLC |