CVE-2026-1728
WSO2 API Manager vulnerability analysis and mitigation

Overview

CVE-2026-1728 is an improper privilege management vulnerability in multiple WSO2 products that allows tokens issued to low-privileged users to access product-level Admin REST APIs, potentially enabling full administrative account takeover. It was published on August 6, 2026, and affects WSO2 API Manager (versions 4.0.0–4.6.0), WSO2 API Control Plane (4.5.0–4.6.0), WSO2 Universal Gateway (4.5.0–4.6.0), and WSO2 Traffic Manager (4.5.0–4.6.0), as well as associated Carbon API Manager library components. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, WSO2 Advisory).

Technical details

The root cause is classified as CWE-269 (Improper Privilege Management): tokens issued to low-privileged users are not sufficiently scoped or validated, allowing them to be presented to Admin REST API endpoints that should require elevated privileges. An attacker who possesses a valid low-privileged account and can obtain a token for it can craft API requests directly to administrative endpoints without any additional privilege escalation steps. The attack is network-based, requires no user interaction, and has low complexity once a valid token is in hand. No public proof-of-concept code has been identified at this time (GitHub Advisory, WSO2 Advisory).

Impact

Successful exploitation grants a low-privileged attacker full administrative control over affected WSO2 products, with high impact to confidentiality, integrity, and availability. An attacker could create or modify administrative accounts, alter API configurations, exfiltrate sensitive data managed through the API platform, or disrupt services. Given that WSO2 API Manager and related products often serve as central API gateways in enterprise environments, compromise could facilitate lateral movement to downstream systems and APIs managed through the platform (GitHub Advisory, WSO2 Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies the vulnerability as automatable with total technical impact, indicating that exploitation could be scripted at scale. The EPSS score is approximately 0.297% (22nd percentile), suggesting a currently low but non-negligible probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing WSO2 API Manager, API Control Plane, Universal Gateway, or Traffic Manager instances running vulnerable versions (e.g., API Manager < 4.6.0.12) using tools like Shodan or Censys, searching for WSO2-specific banners or endpoints.
  2. Obtain a low-privileged account: Register or use an existing low-privileged user account on the target WSO2 deployment (e.g., a standard API consumer account).
  3. Acquire a valid token: Authenticate as the low-privileged user via the WSO2 token endpoint (e.g., /oauth2/token) to obtain a valid OAuth2 access token.
  4. Access Admin REST API: Use the obtained token in an HTTP Authorization header to invoke Admin REST API endpoints (e.g., /api/am/admin/v4/ routes) that are intended to be restricted to administrators.
  5. Achieve administrative takeover: Leverage admin API access to create new admin-level accounts, modify existing user roles, extract sensitive configuration data, or alter API policies to establish persistent access (GitHub Advisory, WSO2 Advisory).

Indicators of compromise

  • Network: Unexpected HTTP requests from low-privileged user tokens to Admin REST API paths (e.g., /api/am/admin/) in API gateway or application logs; unusual volume of admin API calls from non-administrative source IPs.
  • Logs: WSO2 access logs showing successful 2xx responses to /api/am/admin/ endpoints authenticated with tokens belonging to non-admin user accounts; audit logs recording admin-level operations (user creation, role modification) initiated by low-privileged accounts.
  • Application Behavior: Newly created administrative accounts with no corresponding legitimate provisioning activity; unexpected changes to API policies, throttling configurations, or user roles in the WSO2 management console.
  • Authentication Events: Token issuance events for low-privileged accounts followed immediately by admin API invocations, particularly from the same source IP in rapid succession.

Mitigation and workarounds

WSO2 has released patched versions addressing this vulnerability. Organizations should upgrade to the following fixed versions: WSO2 API Manager ≥ 4.0.0.384, 4.1.0.248, 4.2.0.188, 4.3.0.99, 4.4.0.63, 4.5.0.48, or 4.6.0.12; WSO2 API Control Plane ≥ 4.5.0.49 or 4.6.0.13; WSO2 Universal Gateway ≥ 4.5.0.48 or 4.6.0.12; WSO2 Traffic Manager ≥ 4.5.0.47 or 4.6.0.12. As interim mitigations, restrict network access to Admin REST API endpoints at the firewall or load balancer level, enforce strict token scope validation, and audit existing tokens issued to low-privileged accounts. Review API gateway policies to ensure admin endpoints require explicit elevated-privilege scopes (WSO2 Advisory, GitHub Advisory).

Community reactions

Security news outlet SecurityOnline.info covered the vulnerability shortly after disclosure, noting the account takeover risk in WSO2 products. The vulnerability was also discussed on Reddit's r/pwnhub in a daily CVE brief and received attention on social platforms including Bluesky and Mastodon (infosec.exchange). Community reaction has focused on the high CVSS score and the broad range of affected WSO2 product versions, though the requirement for a pre-existing low-privileged account has been noted as a partial mitigating factor in terms of real-world exploitability.

Additional resources


SourceThis report was generated using AI

Related WSO2 API Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5430CRITICAL10
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-1728CRITICAL9.8
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2025-15039CRITICAL9.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-0637MEDIUM4.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:identity_server
NoYesAug 06, 2026
CVE-2025-13736LOW3.7
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management