Wso2

Identity Server

83 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 06.08.2026 08:16:27
  • Zuletzt bearbeitet 10.08.2026 14:00:58

When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness checks. This allows a subject to be associated with an u...

  • EPSS 0.17%
  • Veröffentlicht 06.08.2026 08:16:26
  • Zuletzt bearbeitet 09.08.2026 14:25:39

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidate...

  • EPSS 0.15%
  • Veröffentlicht 20.07.2026 08:06:39
  • Zuletzt bearbeitet 19.08.2026 19:29:34

The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacke...

  • EPSS 0.16%
  • Veröffentlicht 06.07.2026 10:16:53
  • Zuletzt bearbeitet 09.07.2026 13:04:39

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. ...

  • EPSS 0.18%
  • Veröffentlicht 04.07.2026 20:38:49
  • Zuletzt bearbeitet 09.07.2026 18:47:41

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning proc...

  • EPSS 0.16%
  • Veröffentlicht 04.07.2026 12:49:06
  • Zuletzt bearbeitet 09.07.2026 17:55:35

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS appl...

  • EPSS 0.37%
  • Veröffentlicht 11.05.2026 12:16:11
  • Zuletzt bearbeitet 27.05.2026 19:13:13

Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations. A malicious actor with privileges to configure ada...

  • EPSS 0.32%
  • Veröffentlicht 11.05.2026 12:16:10
  • Zuletzt bearbeitet 27.05.2026 19:34:00

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, caus...

  • EPSS 0.23%
  • Veröffentlicht 11.05.2026 10:16:12
  • Zuletzt bearbeitet 27.05.2026 19:50:11

Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security control that should prevent access to accounts that...

  • EPSS 0.18%
  • Veröffentlicht 11.05.2026 10:16:11
  • Zuletzt bearbeitet 27.05.2026 19:54:32

The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-force and soc...