GHSA-88j3-cjwq-qqvvCriticalCVSS 9.8

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used...

Published
August 6, 2026
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.

Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.

🔗 References (3)