Authentication Token Vulnerability in WSO2 Platform
CVE-2025-12317
5MEDIUM
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2025-12317?
This vulnerability presents a significant issue within WSO2 Identity Server, where the removal of internal user roles does not trigger the invalidation of existing authentication tokens linked to that user. Consequently, users can maintain their unauthorized access rights and perform actions that should be restricted, as their authentication tokens remain valid until they naturally expire. This flaw underscores the importance of effective role management and security mechanisms to prevent unauthorized access to sensitive resources.
Affected Version(s)
WSO2 Enterprise Integrator 6.6.0 < 6.6.0.228
WSO2 Identity Server 5.11.0 < 5.11.0.423
