The SOAP admin service in WSO2 products has a security vulnerability that allows the creation of new user accounts regardless of the self-registration configuration settings.
id: CVE-2024-7097
info:
name: WSO2 User Registration - Arbitrary Account Creation
author: iamno
...