vulnerability

WSO2 Multiple Products: CVE-2025-9152: Missing Authentication for Critical Functionplugins/VulnCentricContentRemoteScanner/wso2-multiple-product

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Oct 16, 2025
Added
Oct 20, 2025
Modified
Oct 20, 2025

Description

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint.
A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.

Solution

wso2-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.