← Back to CVE List
Vulnerability Intelligence Report
Improper Privilege Management in Multiple WSO2 API Manager via keymanager-operations DCR Endpoint

CVE-2025-9152

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.68%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-306 ↗CWE-306 Missing Authentication for Critical Function

Affected Products & Versions

Vendor Product Affected Versions
WSO2 WSO2 API Manager 0 < 3.2.0 (unknown), 3.2.0 < 3.2.0.437 (affected), 3.2.1 < 3.2.1.57 (affected), 4.0.0 < 4.0.0.357 (affected), 4.1.0 < 4.1.0.221 (affected), 4.2.0 < 4.2.0.159 (affected), 4.3.0 < 4.3.0.72 (affected), 4.4.0 < 4.4.0.35 (affected), 4.5.0 < 4.5.0.19 (affected)
WSO2 WSO2 API Control Plane 4.5.0 < 4.5.0.20 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.679%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityWSO2 LLC · Vendor · USA
Reserved2025-08-19T08:48:03
Published2025-10-16T12:37:00
Last Updated2025-10-17T16:00:41

LINK COPIED TO CLIPBOARD