
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10611 is an authentication and authorization bypass vulnerability affecting multiple WSO2 products due to insufficient access control implementation in certain REST APIs. Unauthenticated attackers can invoke protected administrative REST API endpoints without proper validation, potentially gaining full administrative access. The vulnerability was published on October 16–17, 2025, with a patch advisory released by WSO2 on November 21, 2025. Affected products include WSO2 API Manager (versions 2.1.0–4.5.0), Identity Server (5.3.0–7.1.0), Identity Server as Key Manager (5.3.0–5.10.0), Open Banking AM/KM/IAM, Universal Gateway 4.5.0, API Control Plane 4.5.0, and Traffic Manager 4.5.0. The CVSS v3.1 base score is 9.8 (Critical) (WSO2 Advisory, Red Hat CVE).
The root cause is classified as CWE-863 (Incorrect Authorization) — the affected WSO2 products fail to properly enforce authentication and authorization checks on certain REST API endpoints, allowing those endpoints to be invoked without credentials. The attack vector is network-based, requires no privileges, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker. A researcher published a detailed write-up titled "WSO2 2: The Many Ways to Bypass Authentication" covering multiple authentication bypass techniques across WSO2 products, which was discussed on Reddit's netsec community (Researcher Blog, Reddit netsec). A related SSRF research post was also published by the same researcher (SSRF Research).
Successful exploitation allows an unauthenticated remote attacker to perform arbitrary administrative operations on affected WSO2 systems, including creating or modifying users, altering API configurations, and accessing sensitive identity and API management data. The vulnerability carries high confidentiality, integrity, and availability impact, meaning attackers can exfiltrate sensitive data, tamper with configurations, and potentially disrupt services. In environments where WSO2 Identity Server or API Manager serves as a central identity or API gateway, compromise could enable lateral movement across integrated systems and downstream services (WSO2 Advisory, Red Hat CVE).
/api/identity/, /api/am/admin/, /services/) originating from unknown or external IP addresses without valid Authorization headers.WSO2 released a security advisory (WSO2-2025-4585) on November 21, 2025, with patches for all affected products. Organizations should apply the latest available updates for their specific WSO2 product versions as detailed in the advisory. As an interim workaround, restrict network access to WSO2 administrative REST API endpoints using firewall rules or reverse proxy ACLs to limit exposure to trusted IP ranges only. Deploying a WAF with updated signatures (e.g., Citrix NetScaler WAF v167/r1217) can provide additional detection and blocking capability (WSO2 Advisory, Citrix WAF Update).
Security researcher crnkovic published a detailed technical write-up titled "WSO2 2: The Many Ways to Bypass Authentication in WSO2" which gained significant traction on Reddit's r/netsec and r/cybersecurity communities, highlighting multiple authentication bypass techniques (Researcher Blog, Reddit netsec). SecurityOnline.info covered both the initial WSO2 patch release and the researcher's detailed disclosure (SecurityOnline Patch, SecurityOnline Research). The vulnerability was also discussed on Bluesky and LinkedIn by infosec community members, and a blog post warned of "WSO2 Zero Day Alert" urging immediate patching (Crypto Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."