CVE-2025-10611: Potential Broken Access Control in Multiple WSO2 Products via System REST APIs
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation.
Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10611?
CVE-2025-10611 is classified as a high-severity vulnerability due to its potential for authentication and authorization bypass.
How do I fix CVE-2025-10611?
To fix CVE-2025-10611, ensure that proper access control measures are implemented for the affected REST APIs in WSO2 Products.
What types of WSO2 Products are affected by CVE-2025-10611?
CVE-2025-10611 affects multiple WSO2 Products that expose certain REST APIs without sufficient access controls.
What are the risks associated with exploiting CVE-2025-10611?
Exploitation of CVE-2025-10611 may allow unauthorized users to access sensitive functions of WSO2 Products, leading to data breaches.
Is there a patch available for CVE-2025-10611?
Yes, WSO2 has released a patch that addresses the access control issues related to CVE-2025-10611.