WSO2 products vulnerable to privilege escalation due to business logic flaw in SOAP admin services
Moderate severity
GitHub Reviewed
Published
May 30, 2025
to the GitHub Advisory Database
•
Updated Jun 4, 2025
Description
Published by the National Vulnerability Database
May 30, 2025
Published to the GitHub Advisory Database
May 30, 2025
Reviewed
Jun 4, 2025
Last updated
Jun 4, 2025
A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a new user with elevated permissions only when all of the following conditions are met:
Exploiting this vulnerability allows malicious actors to assign higher privileges to self-registered users, bypassing intended access control mechanisms.
References