CVE-2025-5717: WSO2 API Control Plane

High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.

Affected products

  • WSO2 API Control Plane: version 4.5.0 only
  • WSO2 API Manager: version 3.0.0 only; version 3.1.0 only; version 3.2.0 only; version 3.2.1 only; version 4.0.0 only; version 4.1.0 only; …
  • WSO2 Open Banking AM: version 2.0.0 only
  • WSO2 Traffic Manager: version 4.5.0 only

Published 2025-09-23. Last modified 2026-06-17.