Access Control Issue in WSO2 Secret Type Management API
CVE-2025-14779

3.8LOW

What is CVE-2025-14779?

The Secret Type Management REST API in WSO2 has a vulnerability that compromises access controls during the deletion of secret types. When the on-delete cascade logic is activated, it mistakenly allows for secrets linked to the specified secret type to be erased across all organizations. This flaw poses a risk of unintentional deletion of critical secrets, which can result in significant operational disruptions, service failures, or even denial-of-service scenarios. Only users with delete permissions, typically assigned to administrators, are able to trigger this vulnerability, but the consequences can impact the entire deployment if exploited.

Affected Version(s)

WSO2 Carbon Identity API Server Secret Management Common 1.2.3 < 1.2.3.7

WSO2 Carbon Identity API Server Secret Management Common 1.2.23 < 1.2.23.11

WSO2 Carbon Identity API Server Secret Management Common 1.3.83 < 1.3.83.16

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.