CVE-2025-9804: Improper Access Control in Multiple WSO2 Products via Internal SOAP Admin Services and System REST APIs
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information.
This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9804?
CVE-2025-9804 is classified as a high-severity vulnerability due to improper access control.
How do I fix CVE-2025-9804?
To address CVE-2025-9804, ensure proper permission enforcement on WSO2 SOAP Admin Services and System REST APIs.
Which WSO2 products are affected by CVE-2025-9804?
CVE-2025-9804 affects multiple WSO2 products that utilize internal SOAP Admin Services and System REST APIs.
What kind of exploitation is possible with CVE-2025-9804?
An attacker with low privileges may exploit CVE-2025-9804 to perform unauthorized operations and access sensitive resources.
Is there a patch available for CVE-2025-9804?
Yes, WSO2 provides security updates to patch CVE-2025-9804, and users should apply these updates as soon as possible.