CVE-2025-14779Low· 3.8▾ SunlitThe Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associ…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations.
Exploitation of this vulnerability can result in the unintended deletion of secrets across the entire deployment, potentially causing configuration failures, service interruptions, and a denial-of-service condition. This vulnerability requires delete permissions for the Secret Type Management REST API, which are by default only granted to administrators.
identity_server >= 6.0.0, < 6.0.0.261identity_server >= 6.1.0, < 6.1.0.262identity_server >= 7.1.0, < 7.1.0.46Upgrade past the affected range:
identity_server 7.1.0.46Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13909Medium· 4.3The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators
CVE-2025-11850Medium· 4.3When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and uniqueness checks
CVE-2025-12627Low· 2.4The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions
CVE-2025-12107High· 8.4The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input
CVE-2022-0330High· 7.8A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU
CVE-2026-35385High· 7.5In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).