CVE-2025-11093P3HIGHCVSS 7.2≥ 2.1.7.wso2v227, < 2.1.7.wso2v227_99·≥ 2.1.7.wso2v271, < 2.1.7.wso2v271_88+9 more2025-11-05
CVE-2025-11093 [HIGH] CWE-94 CVE-2025-11093: An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restr
An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integration runtime environment.
By default, access to these scripting engines is limited to administrators
nvd