User Impersonation Vulnerability in WSO2 Identity Server
CVE-2025-12627
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2025-12627?
The user impersonation flow in WSO2 Identity Server demonstrates a critical flaw in managing refresh tokens associated with impersonated sessions. When an attacker successfully obtains an access token for a masqueraded user, they can exploit this vulnerability by leveraging the refresh token grant mechanism to generate new access tokens. This not only extends their capacity to act as the genuine user but also jeopardizes the integrity of the user's actions, leading to lost traceability and compromised log integrity. Organizations relying on WSO2 Identity Server must address this vulnerability immediately to safeguard against unauthorized actions executed under the guise of legitimate users.
Affected Version(s)
WSO2 Carbon OAuth 7.0.26 < 7.0.26.83
WSO2 Carbon OAuth 7.0.259 < 7.0.259.31
WSO2 Identity Server 7.0.0 < 7.0.0.130
