# CVE-2025-8325

## Summary

- **CVE ID:** CVE-2025-8325
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
- **CWE:** CWE-281
- **Published:** May 11, 2026
- **Last Modified:** May 11, 2026

## Description

The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions.

A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments.

## Affected Products

- WSO2 — WSO2 API Control Plane (4.5.0)
- WSO2 — WSO2 Universal Gateway (4.5.0)
- WSO2 — WSO2 Traffic Manager (4.5.0)
- WSO2 — WSO2 API Manager (0)
- WSO2 — WSO2 API Manager (3.2.0)
- WSO2 — WSO2 API Manager (3.2.1)
- WSO2 — WSO2 API Manager (4.0.0)
- WSO2 — WSO2 API Manager (4.1.0)
- WSO2 — WSO2 API Manager (4.2.0)
- WSO2 — WSO2 API Manager (4.3.0)
- WSO2 — WSO2 API Manager (4.4.0)
- WSO2 — WSO2 API Manager (4.5.0)
- WSO2 — WSO2 Carbon API Management Implementation (6.7.206)
- WSO2 — WSO2 Carbon API Management Implementation (6.7.210)
- WSO2 — WSO2 Carbon API Management Implementation (9.0.174)
- WSO2 — WSO2 Carbon API Management Implementation (9.20.74)
- WSO2 — WSO2 Carbon API Management Implementation (9.28.116)
- WSO2 — WSO2 Carbon API Management Implementation (9.29.120)
- WSO2 — WSO2 Carbon API Management Implementation (9.30.67)
- WSO2 — WSO2 Carbon API Management Implementation (9.31.86)
- WSO2 — WSO2 Carbon API Management Implementation (9.32.75)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (6.7.206)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (6.7.210)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (9.0.174)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (9.20.74)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (9.28.116)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (9.29.120)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (9.30.67)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (9.31.86)
- WSO2 — WSO2 Carbon API Manager Rest API Utility (9.32.75)

## References

- [CNA](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4401/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._