CVE Feed

    Dashboard / CVE / CVE-2025-9804

    CVE-2025-9804

    An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.

    Published:Oct 16, 2025
    Last Modified:Nov 21, 2025
    EPS:Oct 16, 2025
    EPSS Score:0.00043
    CVSS Score:8.9

    Affected Products

    Vendor
    Wso2
    Product
    Api Control Plane
    Vendor
    Wso2
    Product
    Api Manager
    Vendor
    Wso2
    Product
    Api Manager Analytics
    Vendor
    Wso2
    Product
    Carbon
    Vendor
    Wso2
    Product
    Carbon Identity Application Authentication Framework
    Vendor
    Wso2
    Product
    Data Analytics Server
    Vendor
    Wso2
    Product
    Enterprise Integrator
    Vendor
    Wso2
    Product
    Enterprise Mobility Manager
    Vendor
    Wso2
    Product
    Enterprise Service Bus
    Vendor
    Wso2
    Product
    Identity Server
    Vendor
    Wso2
    Product
    Identity Server Analytics
    Vendor
    Wso2
    Product
    Identity Server As Key Manager
    Vendor
    Wso2
    Product
    Open Banking Am
    Vendor
    Wso2
    Product
    Open Banking Iam
    Vendor
    Wso2
    Product
    Open Banking Km
    Vendor
    Wso2
    Product
    Traffic Manager
    Vendor
    Wso2
    Product
    Universal Gateway

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High