EXECUTIVE SUMMARY:
A security researcher disclosed three critical vulnerabilities — CVE-2025-9152, CVE-2025-10611, and CVE-2025-9804 — in widely used API management and identity platforms that allow unauthenticated remote attackers to gain administrator privileges and, in some cases, execute arbitrary code. The flaws stem from regex-based access control misconfigurations where permissions and endpoint protection rules are defined separately from application logic, leading to authentication bypass and privilege escalation. CVE-2025-9152 arises from weak regular expressions that fail to properly secure OAuth endpoints, exposing client secrets and enabling unauthorized administrative access. CVE-2025-10611 exploits HTTP method case sensitivity and path normalization flaws to bypass authentication checks entirely. CVE-2025-9804 affects older SOAP-based endpoints, allowing low-privilege or self-registered users to escalate to administrative roles.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A security researcher disclosed three critical vulnerabilities — CVE-2025-9152, CVE-2025-10611, and CVE-2025-9804 — in widely used API management and identity platforms that allow unauthenticated remote attackers to gain administrator privileges and, in some cases, execute arbitrary code. The flaws stem from regex-based access control misconfigurations where permissions and endpoint protection rules are defined separately from application logic, leading to authentication bypass and privilege escalation. CVE-2025-9152 arises from weak regular expressions that fail to properly secure OAuth endpoints, exposing client secrets and enabling unauthorized administrative access. CVE-2025-10611 exploits HTTP method case sensitivity and path normalization flaws to bypass authentication checks entirely. CVE-2025-9804 affects older SOAP-based endpoints, allowing low-privilege or self-registered users to escalate to administrative roles.[emaillocker id="1283"]
These vulnerabilities highlight the dangers of relying on regex-based access control for authentication. Organizations are urged to review their access control mechanisms and apply available security patches promptly.
RECOMMENDATION:
We strongly recommend you update WSO2 API Manager to below version link: CVE-2025-9152 : https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/
REFERENCES:
The following reports contain further technical details:
https://securityonline.info/researcher-details-critical-authentication-bypasses-in-wso2-api-manager-and-identity-server/