CVE-2026-1728
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Published:Aug 6, 2026
Last Modified:Aug 7, 2026
EPS:Aug 6, 2026
EPSS Score:0.00297
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Wso2
Product
Api Control Plane
Wso2
Api Control Plane
Vendor
Wso2
Product
Api Manager
Wso2
Api Manager
Vendor
Wso2
Product
Traffic Manager
Wso2
Traffic Manager
Vendor
Wso2
Product
Universal Gateway
Wso2
Universal Gateway
Vendor
Wso2
Product
Wso2 Api Control Plane
Wso2
Wso2 Api Control Plane
Vendor
Wso2
Product
Wso2 Api Manager
Wso2
Wso2 Api Manager
Vendor
Wso2
Product
Wso2 Carbon Api Manager Rest Api Common Functions
Wso2
Wso2 Carbon Api Manager Rest Api Common Functions
Vendor
Wso2
Product
Wso2 Carbon Api Manager Rest Api Utility
Wso2
Wso2 Carbon Api Manager Rest Api Utility
Vendor
Wso2
Product
Wso2 Traffic Manager
Wso2
Wso2 Traffic Manager
Vendor
Wso2
Product
Wso2 Universal Gateway
Wso2
Wso2 Universal Gateway
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
