CVE-2025-8325
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments.
Published:May 11, 2026
Last Modified:May 27, 2026
EPS:May 11, 2026
EPSS Score:0.00038
CVSS Score:6.3
Affected Products
Vendor
Product
Action
Vendor
Wso2
Product
Api Control Plane
Wso2
Api Control Plane
Vendor
Wso2
Product
Api Manager
Wso2
Api Manager
Vendor
Wso2
Product
Traffic Manager
Wso2
Traffic Manager
Vendor
Wso2
Product
Universal Gateway
Wso2
Universal Gateway
Vendor
Wso2
Product
Wso2 Api Control Plane
Wso2
Wso2 Api Control Plane
Vendor
Wso2
Product
Wso2 Api Manager
Wso2
Wso2 Api Manager
Vendor
Wso2
Product
Wso2 Carbon Api Management Implementation
Wso2
Wso2 Carbon Api Management Implementation
Vendor
Wso2
Product
Wso2 Carbon Api Manager Rest Api Utility
Wso2
Wso2 Carbon Api Manager Rest Api Utility
Vendor
Wso2
Product
Wso2 Traffic Manager
Wso2
Wso2 Traffic Manager
Vendor
Wso2
Product
Wso2 Universal Gateway
Wso2
Wso2 Universal Gateway
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
