Vulnerability Intelligence Report
Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint
CVE-2025-9152
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.68%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-306 ↗CWE-306 Missing Authentication for Critical Function
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| WSO2 | WSO2 API Manager | 0 < 3.2.0 (unknown), 3.2.0 < 3.2.0.437 (affected), 3.2.1 < 3.2.1.57 (affected), 4.0.0 < 4.0.0.357 (affected), 4.1.0 < 4.1.0.221 (affected), 4.2.0 < 4.2.0.159 (affected), 4.3.0 < 4.3.0.72 (affected), 4.4.0 < 4.4.0.35 (affected), 4.5.0 < 4.5.0.19 (affected) |
| WSO2 | WSO2 API Control Plane | 4.5.0 < 4.5.0.20 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.679%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | WSO2 LLC · Vendor · USA |
| Reserved | 2025-08-19T08:48:03 |
| Published | 2025-10-16T12:37:00 |
| Last Updated | 2025-10-17T16:00:41 |
Community Chatter & Buzz