CVE-2024-8122Medium· 5.9▾ SunlitThe WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious ac…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious actors to conduct brute force attacks by repeatedly guessing the OTP.
The absence of automatic expiration for OTPs grants attackers an unlimited timeframe to attempt guessing the correct code. A successful brute force attack can lead to an MFA bypass, resulting in the unauthorized takeover of a user's account and compromising the security and privacy of both the individual and the system.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13166Low· 3.7The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …
CVE-2025-12624Medium· 6.0Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server
CVE-2025-12627Low· 2.4The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions
CVE-2026-5430Critical· 10.0The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported
CVE-2026-3418Critical· 9.1Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution
CVE-2025-13590Critical· 9.1Authenticated arbitrary file upload via a System REST API requiring administrator permission.