CVE-2025-11093

8.4

WSO2 · Multiple Products (Micro Integrator, API Manager, Enterprise Integrator, Universal Gateway, API Control Plane, Traffic Manager)

A code injection vulnerability in WSO2 products allows authenticated users with elevated privileges to execute arbitrary code via the GraalJS and NashornJS Script Mediator engines.

Executive summary

WSO2 products are vulnerable to arbitrary code execution, posing a critical risk to the integration runtime environment for organizations using these platforms.

Vulnerability

The flaw stems from insufficient security restrictions within the GraalJS and NashornJS Script Mediator engines. Authenticated users with administrative or API creator privileges can leverage these engines to perform unauthorized code execution within the integration runtime.

Business impact

The ability to execute arbitrary code allows an attacker to gain full control over the integration runtime, potentially leading to total system compromise, data exfiltration, or the disruption of critical API and integration services. With a CVSS score of 8.4, this vulnerability represents a high-severity threat that could lead to significant operational downtime and the loss of sensitive data processed by WSO2 middleware.

Remediation

Immediate Action: Upgrade all affected WSO2 components to the patched build versions specified in the official WSO2 security advisory (WSO2-2025-4510).

Proactive Monitoring: Review administrative audit logs for any unusual activity involving script mediator configurations or unexpected code execution patterns within the integration runtime.

Compensating Controls: Restrict administrative and API creator access to the minimum set of necessary personnel to reduce the attack surface for this authenticated-only flaw.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for full system compromise, organizations must prioritize patching these WSO2 products immediately. Security teams should verify their current build versions against the list provided in the vendor advisory and apply the necessary updates to ensure the security of their integration infrastructure.

More WSO2 CVEs

Sources

Originally found and disclosed by crnković, per the CVE Program record.