CVE-2026-1728

api_control_plane: Improper Privilege Management (CVE-2026-1728)

criticalEPSS 0.5%

Affected

  • wso2/api_control_plane between 4.5.0..4.5.0.49
  • wso2/api_control_plane between 4.6.0..4.6.0.13
  • wso2/api_manager between 4.0.0..4.0.0.384
  • wso2/api_manager between 4.1.0..4.1.0.248
  • wso2/api_manager between 4.2.0..4.2.0.188
  • wso2/api_manager between 4.3.0..4.3.0.99
  • wso2/api_manager between 4.4.0..4.4.0.63
  • wso2/api_manager between 4.5.0..4.5.0.48
  • wso2/api_manager between 4.6.0..4.6.0.12
  • wso2/traffic_manager between 4.5.0..4.5.0.47
  • wso2/traffic_manager between 4.6.0..4.6.0.12
  • wso2/universal_gateway between 4.5.0..4.5.0.48
  • wso2/universal_gateway between 4.6.0..4.6.0.12

Description

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

wso2api_control_plane
4.5.0 – 4.5.0.494.6.0 – 4.6.0.13
wso2api_manager
4.0.0 – 4.0.0.3844.1.0 – 4.1.0.2484.2.0 – 4.2.0.1884.3.0 – 4.3.0.994.4.0 – 4.4.0.634.5.0 – 4.5.0.484.6.0 – 4.6.0.12
wso2traffic_manager
4.5.0 – 4.5.0.474.6.0 – 4.6.0.12
wso2universal_gateway
4.5.0 – 4.5.0.484.6.0 – 4.6.0.12

Metrics

9.8
Source: cna-v3
39.7 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-06 07:33 UTC
CWE-269

Weakness classes (CWE)

  • CWE-269Class

    Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-08-10 12:32 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.49 *cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.13
    • CPE Configuration: OR *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.0.0.384 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.1.0 up to (excluding) 4.1.0.248 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.0.188 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.3.0 up to (excluding) 4.3.0.99 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.4.0 up to (excluding) 4.4.0.63 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.48 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.12
    • CPE Configuration: OR *cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.47 *cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.12
    • CPE Configuration: OR *cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.48 *cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.12
  2. CVE Modified2026-08-06 13:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-1728","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
  3. New CVE Received2026-08-06 08:16 UTC· ed10eef1-636d-4fbe-9993-6890dfa878f8
    • Affected: WSO2 API Manager, WSO2 API Control Plane, WSO2 Universal Gateway (+3)
    • Description: Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-269

Linked advisories