Impact
Tokens issued to a low‑privileged user are not sufficiently restricted, allowing the attacker to use them to call product‑level Admin REST APIs. This elevation can lead to a full takeover of an administrative account, compromising confidentiality, integrity, and availability of the affected WSO2 products. The weakness is a classic privilege escalation scenario marked by CWE‑269.
Affected Systems
The flaw affects several WSO2 products, including WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon API Manager Rest API Common Functions, WSO2 Carbon API Manager Rest API Utility, WSO2 Traffic Manager, and WSO2 Universal Gateway. No specific version information is disclosed, so all current releases may be impacted until a patch is applied.
Risk and Exploitability
The vulnerability scores a CVSS of 9.8, indicating critical severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to already possess a low‑privileged account and be able to obtain a valid token for that account. With that, the attacker can invoke any Admin REST API, making the attack vector a REST API call using an unfiltered token. The attack is feasible in an environment where REST API access is enabled and tokens are not scoped to limit admin rights.
OpenCVE Enrichment