Authentication Token Vulnerability in WSO2 Platform
CVE-2025-12317

5MEDIUM

Key Information:

Vendor

Wso2

Vendor
CVE Published:
6 August 2026

What is CVE-2025-12317?

This vulnerability presents a significant issue within WSO2 Identity Server, where the removal of internal user roles does not trigger the invalidation of existing authentication tokens linked to that user. Consequently, users can maintain their unauthorized access rights and perform actions that should be restricted, as their authentication tokens remain valid until they naturally expire. This flaw underscores the importance of effective role management and security mechanisms to prevent unauthorized access to sensitive resources.

Affected Version(s)

WSO2 Enterprise Integrator 6.6.0 < 6.6.0.228

WSO2 Identity Server 5.11.0 < 5.11.0.423

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.