CVE-2025-12627Low· 2.4▾ SunlitThe user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user.
An attacker who gains access to an impersonated user's access token can exploit this weakness to renew their authorization. This results in the continued ability to perform actions on behalf of the actual user, compromising log integrity and traceability by masking the true actor.
identity_server >= 7.0.0, < 7.0.0.130identity_server >= 7.1.0, < 7.1.0.38Upgrade past the affected range:
identity_server 7.1.0.38Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13909Medium· 4.3The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators
CVE-2025-11850Medium· 4.3When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness checks
CVE-2025-12107High· 8.4The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input
CVE-2025-15039Critical· 9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured
CVE-2025-13736Low· 3.7When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts
CVE-2025-13394Medium· 5.4The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks