CVE-2025-9152: WSO2 API Control Plane
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Affected products
- WSO2 API Control Plane: version 4.5.0 only
- WSO2 API Manager: version 3.2.0 only; version 3.2.1 only; version 4.0.0 only; version 4.1.0 only; version 4.2.0 only; version 4.3.0 only; …
Published 2025-10-16. Last modified 2026-06-17.