CVE-2025-5802
- EPSS 0.25%
- Veröffentlicht 15.09.2026 09:53:53
- Zuletzt bearbeitet 18.09.2026 19:13:15
The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explic...
CVE-2025-15039
- EPSS 0.37%
- Veröffentlicht 06.08.2026 08:16:29
- Zuletzt bearbeitet 29.09.2026 14:10:00
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker ...
CVE-2025-13909
- EPSS 0.21%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 29.09.2026 14:10:00
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead t...
CVE-2023-6837
- EPSS 0.46%
- Veröffentlicht 15.12.2023 10:15:09
- Zuletzt bearbeitet 05.06.2025 09:15:21
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: * An IDP configured for feder...