CVE-2026-1728: WSO2 API Control Plane
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Affected products
- WSO2 API Control Plane: from 4.5.0, before 4.5.0.49 (fixed in 4.5.0.49); from 4.6.0, before 4.6.0.13 (fixed in 4.6.0.13)
- WSO2 API Manager: from 4.0.0, before 4.0.0.384 (fixed in 4.0.0.384); from 4.1.0, before 4.1.0.248 (fixed in 4.1.0.248); from 4.2.0, before 4.2.0.188 (fixed in 4.2.0.188); from 4.3.0, before 4.3.0.99 (fixed in 4.3.0.99); from 4.4.0, before 4.4.0.63 (fixed in 4.4.0.63); from 4.5.0, before 4.5.0.48 (fixed in 4.5.0.48); …
- WSO2 Traffic Manager: from 4.5.0, before 4.5.0.47 (fixed in 4.5.0.47); from 4.6.0, before 4.6.0.12 (fixed in 4.6.0.12)
- WSO2 Universal Gateway: from 4.5.0, before 4.5.0.48 (fixed in 4.5.0.48); from 4.6.0, before 4.6.0.12 (fixed in 4.6.0.12)
Published 2026-08-06. Last modified 2026-08-10.