Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
6.3
CVE-2025-8325EXPLOITEDPATCHED
wso2 · wso2 api control plane

Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations

Description

The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments.

Affected Products

VendorProductVersions
wso2wso2 api control plane4.5.0, 4.5.0, 4.5.0, 3.2.0, 3.2.1, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.5.0, 6.7.206, 6.7.210, 9.0.174, 9.20.74, 9.28.116, 9.29.120, 9.30.67, 9.31.86, 6.7.206, 6.7.210, 9.0.174, 9.20.74, 9.28.116, 9.29.120, 9.30.67, 9.31.86

References

  • https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4401/(vendor-advisory)

Related News (1 articles)

Tier C
VulDB47d ago
CVE-2025-8325 | WSO2 API Control Plane Gateway API permissions
→ No new info (linked only)
CVSS 3.16.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.5.0.184.5.0.173.2.0.4353.2.1.554.0.0.3554.1.0.2194.2.0.1574.3.0.704.4.0.336.7.206.5636.7.210.559.0.174.5139.20.74.3759.28.116.3529.29.120.1779.30.67.1009.31.86.589.32.75
CWECWE-281
PublishedMay 11, 2026
Last enriched47d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-2053EXP
Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
Trending: 54
HIGHCVE-2025-10908EXP
Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized Access
MEDIUMCVE-2024-0391EXP
Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery
MEDIUMCVE-2025-9973
Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover
HIGHCVE-2024-2374
XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 11, 2026
Discovered by ZDM
May 11, 2026
Updated: severity, activelyExploited
May 11, 2026
Actively Exploited
May 11, 2026
Patch Available
May 11, 2026

Version History

v2
Last enriched 47d ago
v2Tier C47d ago

Updated severity to CRITICAL, marked as actively exploited, and noted that no exploit currently exists.

severityactivelyExploited
via VulDB
v147d ago

Initial creation