CVE-2025-15039
- EPSS 0.37%
- Veröffentlicht 06.08.2026 08:16:29
- Zuletzt bearbeitet 12.08.2026 19:32:37
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker ...
CVE-2025-13909
- EPSS 0.21%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 10.08.2026 14:15:12
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead t...
CVE-2023-6837
- EPSS 0.46%
- Veröffentlicht 15.12.2023 10:15:09
- Zuletzt bearbeitet 05.06.2025 09:15:21
Multiple WSO2 products have been identified as vulnerable to perform user impersonatoin using JIT provisioning. In order for this vulnerability to have any impact on your deployment, following conditions must be met: * An IDP configured for feder...