User Store Configuration Issue in WSO2 Identity Server
CVE-2025-11850
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2025-11850?
A configuration issue within WSO2 Identity Server arises when secondary user stores are used. This misconfiguration allows the implicit-association resolver to initialize incorrectly from a secondary user store, effectively bypassing the primary user store. As a result, if the same lookup claim, such as a username or email, exists across both user stores, it creates potential identity confusion. Legitimate accounts in the primary store might fail to associate with their respective accounts on external Identity Providers (IDPs), leading to unintended access restrictions based on secondary account privileges. The vulnerability does not affect systems without secondary user stores or where implicit associations are disabled.
Affected Version(s)
Token Exchange Grant Type For OAuth 1.1.19
WSO2 Identity Server 7.0.0 < 7.0.0.132
WSO2 Identity Server 7.1.0 < 7.1.0.40
