User Store Configuration Issue in WSO2 Identity Server
CVE-2025-11850

4.3MEDIUM

What is CVE-2025-11850?

A configuration issue within WSO2 Identity Server arises when secondary user stores are used. This misconfiguration allows the implicit-association resolver to initialize incorrectly from a secondary user store, effectively bypassing the primary user store. As a result, if the same lookup claim, such as a username or email, exists across both user stores, it creates potential identity confusion. Legitimate accounts in the primary store might fail to associate with their respective accounts on external Identity Providers (IDPs), leading to unintended access restrictions based on secondary account privileges. The vulnerability does not affect systems without secondary user stores or where implicit associations are disabled.

Affected Version(s)

Token Exchange Grant Type For OAuth 1.1.19

WSO2 Identity Server 7.0.0 < 7.0.0.132

WSO2 Identity Server 7.1.0 < 7.1.0.40

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.