VYPR
Moderate severityNVD Advisory· Published May 30, 2025· Updated Dec 3, 2025

Privilege Escalation in Multiple WSO2 Products via SOAP Admin Service Due to Business Logic Flaw

CVE-2024-7096

Description

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met: * SOAP admin services are accessible to the attacker. * The deployment includes an internally used attribute that is not part of the default WSO2 product configuration. * At least one custom role exists with non-default permissions. * The attacker has knowledge of the custom role and the internal attribute used in the deployment.

Exploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.wso2.am:am-parentMaven
>= 2.0.0, < 4.4.04.4.0
org.wso2.is:identity-server-parentMaven
>= 5.2.0, < 7.1.07.1.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.