Authentication Bypass in WSO2 Products with FIDO Authentication
CVE-2025-0672
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 23 September 2025
What is CVE-2025-0672?
An authentication bypass flaw exists in various WSO2 products with FIDO authentication enabled. When a user account is deleted, its FIDO registration data remains, potentially allowing a new account with the same username to associate with this data. If the deleted user attempts to access the system, they can authenticate using their former FIDO credentials, thereby impersonating the new user account. This vulnerability poses significant security risks for deployments utilizing FIDO authentication.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WSO2 Identity Server 5.10.0 < 5.10.0.345
WSO2 Identity Server 5.11.0 < 5.11.0.394
WSO2 Identity Server as Key Manager 5.10.0 < 5.10.0.338
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
