August 28, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-1728NVD

Vulnerability Summary

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs.

Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
Severity Level
CRITICAL(9.8)
Published Date
Aug 6, 2026
Last Modified
Aug 10, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.30%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh