CVE-2026-1728
api_control_plane: Improper Privilege Management (CVE-2026-1728)
Affected
- wso2/api_control_plane
between 4.5.0..4.5.0.49 - wso2/api_control_plane
between 4.6.0..4.6.0.13 - wso2/api_manager
between 4.0.0..4.0.0.384 - wso2/api_manager
between 4.1.0..4.1.0.248 - wso2/api_manager
between 4.2.0..4.2.0.188 - wso2/api_manager
between 4.3.0..4.3.0.99 - wso2/api_manager
between 4.4.0..4.4.0.63 - wso2/api_manager
between 4.5.0..4.5.0.48 - wso2/api_manager
between 4.6.0..4.6.0.12 - wso2/traffic_manager
between 4.5.0..4.5.0.47 - wso2/traffic_manager
between 4.6.0..4.6.0.12 - wso2/universal_gateway
between 4.5.0..4.5.0.48 - wso2/universal_gateway
between 4.6.0..4.6.0.12
Description
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
4.5.0 – 4.5.0.494.6.0 – 4.6.0.134.0.0 – 4.0.0.3844.1.0 – 4.1.0.2484.2.0 – 4.2.0.1884.3.0 – 4.3.0.994.4.0 – 4.4.0.634.5.0 – 4.5.0.484.6.0 – 4.6.0.124.5.0 – 4.5.0.474.6.0 – 4.6.0.124.5.0 – 4.5.0.484.6.0 – 4.6.0.12Metrics
Show all metrics
Weakness classes (CWE)
CWE-269Class
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-10 12:32 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.49 *cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.13
- CPE Configuration: OR *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.0.0.384 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.1.0 up to (excluding) 4.1.0.248 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.2.0 up to (excluding) 4.2.0.188 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.3.0 up to (excluding) 4.3.0.99 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.4.0 up to (excluding) 4.4.0.63 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.48 *cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.12
- CPE Configuration: OR *cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.47 *cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.12
- CPE Configuration: OR *cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* versions from (including) 4.5.0 up to (excluding) 4.5.0.48 *cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:* versions from (including) 4.6.0 up to (excluding) 4.6.0.12
- CVE Modified2026-08-06 13:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-1728","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
- New CVE Received2026-08-06 08:16 UTC· ed10eef1-636d-4fbe-9993-6890dfa878f8
- Affected: WSO2 API Manager, WSO2 API Control Plane, WSO2 Universal Gateway (+3)
- Description: Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-269