CVE-2025-10611
WSO2 API Manager vulnerability analysis and mitigation

Overview

CVE-2025-10611 is an authentication and authorization bypass vulnerability affecting multiple WSO2 products due to insufficient access control implementation in certain REST APIs. Unauthenticated attackers can invoke protected administrative REST API endpoints without proper validation, potentially gaining full administrative access. The vulnerability was published on October 16–17, 2025, with a patch advisory released by WSO2 on November 21, 2025. Affected products include WSO2 API Manager (versions 2.1.0–4.5.0), Identity Server (5.3.0–7.1.0), Identity Server as Key Manager (5.3.0–5.10.0), Open Banking AM/KM/IAM, Universal Gateway 4.5.0, API Control Plane 4.5.0, and Traffic Manager 4.5.0. The CVSS v3.1 base score is 9.8 (Critical) (WSO2 Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization) — the affected WSO2 products fail to properly enforce authentication and authorization checks on certain REST API endpoints, allowing those endpoints to be invoked without credentials. The attack vector is network-based, requires no privileges, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. A researcher published a detailed write-up titled "WSO2 2: The Many Ways to Bypass Authentication" covering multiple authentication bypass techniques across WSO2 products, which was discussed on Reddit's netsec community (Researcher Blog, Reddit netsec). A related SSRF research post was also published by the same researcher (SSRF Research).

Impact

Successful exploitation allows an unauthenticated remote attacker to perform arbitrary administrative operations on affected WSO2 systems, including creating or modifying users, altering API configurations, and accessing sensitive identity and API management data. The vulnerability carries high confidentiality, integrity, and availability impact, meaning attackers can exfiltrate sensitive data, tamper with configurations, and potentially disrupt services. In environments where WSO2 Identity Server or API Manager serves as a central identity or API gateway, compromise could enable lateral movement across integrated systems and downstream services (WSO2 Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing WSO2 API Manager, Identity Server, or related product instances using tools like Shodan or Censys, filtering for known WSO2 management ports (e.g., 9443) and version banners.
  2. Identify vulnerable REST API endpoints: Review WSO2 documentation or the researcher's public write-up to identify REST API endpoints that lack proper authentication enforcement in the affected versions.
  3. Craft unauthenticated HTTP request: Send a direct HTTP/HTTPS request to a protected administrative REST API endpoint (e.g., user management, application registration, or API configuration endpoints) without supplying authentication credentials or tokens.
  4. Bypass access control: Due to the insufficient access control implementation (CWE-863), the server processes the request without validating authentication or authorization, returning a successful response.
  5. Perform administrative operations: Use the unauthorized access to create admin accounts, modify API policies, extract user credentials or tokens, or reconfigure identity federation settings to establish persistent access (Researcher Blog, WSO2 Advisory).

Indicators of compromise

  • Network: Unexpected HTTP/HTTPS requests to WSO2 administrative REST API endpoints (e.g., /api/identity/, /api/am/admin/, /services/) originating from unknown or external IP addresses without valid Authorization headers.
  • Logs: WSO2 access logs showing successful (HTTP 200) responses to administrative API calls with no associated authentication token or session; repeated API calls to user management or application registration endpoints from a single external IP.
  • File System: Unexpected new user accounts or applications created in the WSO2 management console; unauthorized changes to API policies, identity provider configurations, or role assignments.
  • Process/Behavior: Unusual administrative activity in WSO2 audit logs (e.g., bulk user creation, role escalation, or new OAuth application registration) with no corresponding legitimate admin session (WSO2 Advisory).

Mitigation and workarounds

WSO2 released a security advisory (WSO2-2025-4585) on November 21, 2025, with patches for all affected products. Organizations should apply the latest available updates for their specific WSO2 product versions as detailed in the advisory. As an interim workaround, restrict network access to WSO2 administrative REST API endpoints using firewall rules or reverse proxy ACLs to limit exposure to trusted IP ranges only. Deploying a WAF with updated signatures (e.g., Citrix NetScaler WAF v167/r1217) can provide additional detection and blocking capability (WSO2 Advisory, Citrix WAF Update).

Community reactions

Security researcher crnkovic published a detailed technical write-up titled "WSO2 2: The Many Ways to Bypass Authentication in WSO2" which gained significant traction on Reddit's r/netsec and r/cybersecurity communities, highlighting multiple authentication bypass techniques (Researcher Blog, Reddit netsec). SecurityOnline.info covered both the initial WSO2 patch release and the researcher's detailed disclosure (SecurityOnline Patch, SecurityOnline Research). The vulnerability was also discussed on Bluesky and LinkedIn by infosec community members, and a blog post warned of "WSO2 Zero Day Alert" urging immediate patching (Crypto Blog).

Additional resources


SourceThis report was generated using AI

Related WSO2 API Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-2053CRITICAL10
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesJun 26, 2026
CVE-2026-4249HIGH8.6
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesJul 06, 2026
CVE-2025-13475HIGH7.3
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesJul 04, 2026
CVE-2025-8591MEDIUM6.1
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:identity_server
NoYesJul 06, 2026
CVE-2024-1248MEDIUM5.3
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesJul 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management