Threat Advisory

WSO2 API Manager Vulnerability Allows Full Authentication Bypass

Threat: Vulnerability
Threat Actor Name: -
Threat Actor Type: -
Targeted Region: Global
Alias: -
Threat Actor Region: -
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A security researcher disclosed three critical vulnerabilities — CVE-2025-9152, CVE-2025-10611, and CVE-2025-9804 — in widely used API management and identity platforms that allow unauthenticated remote attackers to gain administrator privileges and, in some cases, execute arbitrary code. The flaws stem from regex-based access control misconfigurations where permissions and endpoint protection rules are defined separately from application logic, leading to authentication bypass and privilege escalation. CVE-2025-9152 arises from weak regular expressions that fail to properly secure OAuth endpoints, exposing client secrets and enabling unauthorized administrative access. CVE-2025-10611 exploits HTTP method case sensitivity and path normalization flaws to bypass authentication checks entirely. CVE-2025-9804 affects older SOAP-based endpoints, allowing low-privilege or self-registered users to escalate to administrative roles.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A security researcher disclosed three critical vulnerabilities — CVE-2025-9152, CVE-2025-10611, and CVE-2025-9804 — in widely used API management and identity platforms that allow unauthenticated remote attackers to gain administrator privileges and, in some cases, execute arbitrary code. The flaws stem from regex-based access control misconfigurations where permissions and endpoint protection rules are defined separately from application logic, leading to authentication bypass and privilege escalation. CVE-2025-9152 arises from weak regular expressions that fail to properly secure OAuth endpoints, exposing client secrets and enabling unauthorized administrative access. CVE-2025-10611 exploits HTTP method case sensitivity and path normalization flaws to bypass authentication checks entirely. CVE-2025-9804 affects older SOAP-based endpoints, allowing low-privilege or self-registered users to escalate to administrative roles.[emaillocker id="1283"]

 

  • CVE-2025-9152 – Improper access control with a CVSS score of 9.8 that allows unauthenticated attackers to exploit missing or weak regular expressions in the access control configuration to leak OAuth client secrets register or modify OAuth clients and obtain administrative access.

 

These vulnerabilities highlight the dangers of relying on regex-based access control for authentication. Organizations are urged to review their access control mechanisms and apply available security patches promptly.

RECOMMENDATION:

We strongly recommend you update WSO2 API Manager to below version link: CVE-2025-9152 : https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4483/

REFERENCES:

The following reports contain further technical details:
https://securityonline.info/researcher-details-critical-authentication-bypasses-in-wso2-api-manager-and-identity-server/

[/emaillocker]
crossmenu