Insufficient Token Restrictions in WSO2 Products Allow Low-privileged User Access

⚠️ CVE-Referenzen: CVE-2026-1728
Wso2 - Wso2 Api Manager - CRITICAL - CVE-2026-1728. This vulnerability affects WSO2 products by failing to adequately restrict tokens issued to low-privileged users. This oversight enables these users to exploit Admin REST APIs, potentially compromising system integrity and leading to a complete takeover of administrative functions. Attackers would need to already possess a low-privileged account and have access to a valid token, which presents a significant risk to organizations relying on secure API management and administrative controls.
Quelle: securityvulnerability.io