CVE-2026-1728
Received Received - Intake

Privilege Escalation in WSO2 Products via Admin REST API

Vulnerability report for CVE-2026-1728, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
wso2 traffic_manager *
wso2 universal_gateway *
wso2 api_control_plane *
wso2 api_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-1728 is a privilege escalation vulnerability in WSO2 products where tokens issued to low-privileged users are not properly restricted. This allows these users to access Admin REST APIs, potentially leading to full administrative account takeover.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized access to Admin REST APIs by low-privileged users. Monitor logs for unusual API calls to admin endpoints, especially from non-admin accounts. Review token issuance and usage patterns for anomalies. Check if tokens issued to low-privileged users have elevated privileges or access to admin resources.

Impact Analysis

If exploited, this vulnerability enables a low-privileged user to gain full administrative access to WSO2 products. This could result in unauthorized control over systems, data breaches, or further network compromise.

Mitigation Strategies

Apply the latest security patches provided by WSO2 for affected products. Restrict token privileges to ensure low-privileged users cannot access admin APIs. Review and revoke any suspicious tokens issued to low-privileged accounts. Monitor admin API access logs for unauthorized activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1728. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart