Vulnerability Intelligence Report
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
CVE-2026-1728
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Privilege Escalation
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-269 ↗CWE-269: Improper Privilege Management
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| WSO2 | WSO2 API Manager | 0 < 4.0.0 (unknown), 4.0.0 < 4.0.0.384 (affected), 4.1.0 < 4.1.0.248 (affected), 4.2.0 < 4.2.0.188 (affected), 4.3.0 < 4.3.0.99 (affected), 4.4.0 < 4.4.0.63 (affected), 4.5.0 < 4.5.0.48 (affected), 4.6.0 < 4.6.0.12 (affected) |
| WSO2 | WSO2 API Control Plane | 4.5.0 < 4.5.0.49 (affected), 4.6.0 < 4.6.0.13 (affected) |
| WSO2 | WSO2 Universal Gateway | 4.5.0 < 4.5.0.48 (affected), 4.6.0 < 4.6.0.12 (affected) |
| WSO2 | WSO2 Traffic Manager | 4.5.0 < 4.5.0.47 (affected), 4.6.0 < 4.6.0.12 (affected) |
| WSO2 | WSO2 Carbon API Manager Rest API Common Functions | 9.0.174 < 9.0.174.550 (affected), 9.28.116 < 9.28.116.404 (affected), 9.29.120 < 9.29.120.221 (affected), 9.30.67 < 9.30.67.146 (affected), 9.31.86 < 9.31.86.130 (affected), 9.32.147 < 9.32.147.26 (affected), 9.33.27 <= * (unaffected) |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.20.74 < 9.20.74.392 (affected), 9.33.27 <= * (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Vulnerability Class
Privilege Escalation
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | WSO2 LLC · Vendor · USA |
| Reserved | 2026-01-31T08:23:56 |
| Published | 2026-08-06T07:33:25 |
| Last Updated | 2026-08-06T12:31:19 |
Community Chatter & Buzz