Account Locking Bypass in WSO2 Identity Server
CVE-2024-6832
5.9MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2024-6832?
A vulnerability exists in the WSO2 Identity Server where the account locking mechanism fails to activate when secondary user stores are unreachable. This flaw results in an inconsistent state for account locking, allowing attackers to repeatedly attempt authentication using invalid credentials. As a result, users linked to accessible user stores can be subjected to brute force attacks without the anticipated lockout penalties, thereby exposing sensitive information and increasing security risks.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.40
WSO2 API Control Plane 4.6.0 < 4.6.0.4
WSO2 API Control Plane 4.6.0 < 4.6.0.5
