CVE-2025-9152

🚨 CRITICAL

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint...

Published
Oct 16, 2025
Last Modified
Oct 21, 2025
Views
2
Bookmarks
0

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.

Affected Products (9)

wso2 - api_control_plane

Version: 4.5.0

wso2 - api_manager

Version: 3.2.0

wso2 - api_manager

Version: 3.2.1

wso2 - api_manager

Version: 4.0.0

wso2 - api_manager

Version: 4.1.0

wso2 - api_manager

Version: 4.2.0

wso2 - api_manager

Version: 4.3.0

wso2 - api_manager

Version: 4.4.0

wso2 - api_manager

Version: 4.5.0

CVSS Scores

CVSS 3.1 9.8
9.8
CRITICAL
CVSS 2.0 9.8

Additional Information

Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
State
Analyzed

Share CVE-2025-9152

Share on Social Media

Copy Link

Embed Code

Request Expert Analysis

Request a professional security analysis for CVE-2025-9152 from our verified experts.

Credits System

Use your credits to get expert analysis from verified security professionals. Purchase more credits anytime!

Add 3 credits for accelerated delivery

Base Cost: 8 credits
Priority Upgrade: + credits
SLA Acceleration: +3 credits
Total Cost:
Your Balance:

Insufficient Credits

You need more credits to submit this request.

Buy Credits

Report Analysis