Unrated severityNVD Advisory· Published Oct 16, 2025· Updated Oct 16, 2025
Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
CVE-2025-10611
Description
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation.
Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.
Affected products
3- WSO2/WSO2 Identity Server as Key Managerv5Range: 5.3.0
- WSO2/WSO2 Open Banking AMv5Range: 1.4.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.