- EPSS 0.24%
- Veröffentlicht 06.08.2026 22:16:41
- Zuletzt bearbeitet 07.08.2026 18:17:06
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privilege...
CVE-2026-0637
- EPSS 0.11%
- Veröffentlicht 06.08.2026 08:16:29
- Zuletzt bearbeitet 12.08.2026 19:29:05
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to t...
CVE-2025-15039
- EPSS 0.37%
- Veröffentlicht 06.08.2026 08:16:29
- Zuletzt bearbeitet 12.08.2026 19:32:37
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker ...
CVE-2025-14779
- EPSS 0.19%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 10.08.2026 14:03:28
The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with tha...
CVE-2025-13909
- EPSS 0.21%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 10.08.2026 14:15:12
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead t...
CVE-2025-13736
- EPSS 0.17%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 12.08.2026 19:36:22
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original inp...
CVE-2025-13394
- EPSS 0.1%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 12.08.2026 19:53:27
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie a...
CVE-2025-12627
- EPSS 0.13%
- Veröffentlicht 06.08.2026 08:16:28
- Zuletzt bearbeitet 10.08.2026 14:17:20
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant t...
CVE-2024-8995
- EPSS 0.12%
- Veröffentlicht 06.08.2026 08:16:27
- Zuletzt bearbeitet 13.08.2026 13:18:42
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization...
CVE-2024-6832
- EPSS 0.24%
- Veröffentlicht 06.08.2026 08:16:27
- Zuletzt bearbeitet 09.08.2026 14:14:01
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attemp...