Vulnerability in WSO2 Product Affecting Authorization Code Management
CVE-2024-8995
4.9MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2024-8995?
The vulnerability pertains to the failure of the WSO2 Identity Server to adequately invalidate authorization codes linked to deleted users. When a user account is deleted, any associated authorization codes should be removed from the system to prevent unauthorized access. However, these codes remain valid, allowing attackers with the right client credentials to misuse them for obtaining access tokens. This potentially compromises sensitive user data by enabling unauthorized access to resources that are no longer meant to be accessible.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.56
WSO2 API Control Plane 4.6.0 < 4.6.0.20
WSO2 API Manager 3.1.0 < 3.1.0.320
