CVE-2026-1728: Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.
Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1728?
CVE-2026-1728 has a critical severity rating of 9.8.
What type of vulnerability is CVE-2026-1728?
CVE-2026-1728 is a privilege escalation vulnerability affecting multiple WSO2 products.
How do I fix CVE-2026-1728?
Fixing CVE-2026-1728 involves applying the latest security patches provided by WSO2 for affected products.
What can attackers do by exploiting CVE-2026-1728?
Exploiting CVE-2026-1728 allows a low-privileged user to access admin-level functionality through the Admin REST APIs.
Which software is affected by CVE-2026-1728?
CVE-2026-1728 affects multiple WSO2 products that utilize System REST APIs.