Access Control Issue in WSO2 Secret Type Management API
CVE-2025-14779
Key Information:
- Vendor
Wso2
- Status
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2025-14779?
The Secret Type Management REST API in WSO2 has a vulnerability that compromises access controls during the deletion of secret types. When the on-delete cascade logic is activated, it mistakenly allows for secrets linked to the specified secret type to be erased across all organizations. This flaw poses a risk of unintentional deletion of critical secrets, which can result in significant operational disruptions, service failures, or even denial-of-service scenarios. Only users with delete permissions, typically assigned to administrators, are able to trigger this vulnerability, but the consequences can impact the entire deployment if exploited.
Affected Version(s)
WSO2 Carbon Identity API Server Secret Management Common 1.2.3 < 1.2.3.7
WSO2 Carbon Identity API Server Secret Management Common 1.2.23 < 1.2.23.11
WSO2 Carbon Identity API Server Secret Management Common 1.3.83 < 1.3.83.16
