Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-1728

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 21.9%
CVSS Severity
CVSS v3 Score 9.8


Contact Us

Shodan ® - All rights reserved