CVE-2025-9804
CVE-2025-9804 is a critical-severity vulnerability in Wso2 Api Control Plane with a CVSS 3.x base score of 9.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: Critical (CVSS 3.x base score 9.6)
- EPSS exploit prediction: 1% (42nd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-34754
- Weakness: CWE-284
- Affected product: Wso2 Api Control Plane
- Published:
- Last modified:
Description
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
Frequently asked questions
- What is CVE-2025-9804?
- An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
- How severe is CVE-2025-9804?
- CVE-2025-9804 has a CVSS 3.x base score of 9.6, rated critical severity. It is exploitable over an adjacent network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-9804 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (42nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-9804?
- CVE-2025-9804 primarily affects Wso2 Api Control Plane. In total, 59 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2025-9804?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2025-9804 have an EU (EUVD) identifier?
- Yes. CVE-2025-9804 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-34754.
- When was CVE-2025-9804 published?
- CVE-2025-9804 was published on 2025-10-16 and last updated on 2026-06-17.
References
Affected products (59)
- cpe:2.3:a:wso2:api_control_plane:4.5.0:-:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:2.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:2.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:4.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:4.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:4.3.0:-:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:4.4.0:-:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager:4.5.0:-:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager_analytics:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager_analytics:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager_analytics:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:api_manager_analytics:2.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:data_analytics_server:3.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:data_analytics_server:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:enterprise_integrator:6.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:enterprise_integrator:6.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:enterprise_mobility_manager:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:enterprise_service_bus:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:6.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:6.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:wso2:identity_server:7.0.0:-:*:*:*:*:*:*
More vulnerabilities in Wso2 Api Control Plane
- CVE-2026-5430 — Critical (CVSS 10.0): The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or…
- CVE-2026-1728 — Critical (CVSS 9.8): Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access…
- CVE-2025-9312 — Critical (CVSS 9.8): A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST…
- CVE-2025-9152 — Critical (CVSS 9.8): An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and…
- CVE-2025-10611 — Critical (CVSS 9.8): Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks…
- CVE-2025-15039 — Critical (CVSS 9.4): The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all…
All CVEs affecting Wso2 Api Control Plane →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.
- CVE-2026-20315 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-70921 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-66803 — Critical (CVSS 10.0): Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-58630 — Critical (CVSS 10.0): Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-60358 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
Browse all CWE-284 (Improper Access Control) vulnerabilities →