PT-2025-42460 · Wso2 · Wso2 Products

Published

2025-10-16

·

Updated

2025-11-21

·

CVE-2025-10611

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WSO2 Products (affected versions not specified)
Description An insufficient access control implementation exists in multiple WSO2 Products. This allows bypassing authentication and authorization checks for certain REST APIs, enabling invocation without proper validation. Successful exploitation could grant a malicious actor administrative access and the ability to perform unauthorized operations. The flaw compromises the security barrier restricting access to administrative or sensitive functions, permitting unauthorized execution of privileged operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-10611

Affected Products

Wso2 Products