An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint.

A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Advisories

No advisories yet.

Fixes

Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/#solution


Workaround

No workaround given by the vendor.

History

Fri, 17 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Thu, 16 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Description An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Title Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2025-10-17T16:00:41.854Z

Reserved: 2025-08-19T08:48:03.616Z

Link: CVE-2025-9152

cve-icon Vulnrichment

Updated: 2025-10-16T12:57:59.271Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-16T13:15:41.840

Modified: 2025-10-17T16:15:39.550

Link: CVE-2025-9152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.