User Impersonation Vulnerability in WSO2 Identity Server
CVE-2025-12627

2.4LOW

Key Information:

Vendor

Wso2

Vendor
CVE Published:
6 August 2026

What is CVE-2025-12627?

The user impersonation flow in WSO2 Identity Server demonstrates a critical flaw in managing refresh tokens associated with impersonated sessions. When an attacker successfully obtains an access token for a masqueraded user, they can exploit this vulnerability by leveraging the refresh token grant mechanism to generate new access tokens. This not only extends their capacity to act as the genuine user but also jeopardizes the integrity of the user's actions, leading to lost traceability and compromised log integrity. Organizations relying on WSO2 Identity Server must address this vulnerability immediately to safeguard against unauthorized actions executed under the guise of legitimate users.

Affected Version(s)

WSO2 Carbon OAuth 7.0.26 < 7.0.26.83

WSO2 Carbon OAuth 7.0.259 < 7.0.259.31

WSO2 Identity Server 7.0.0 < 7.0.0.130

References

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.