Wso2 Carbon Abstract Otp Authenticator
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Wso2 Carbon Abstract Otp Authenticator.
By the Year
In 2026 there have been 1 vulnerability in Wso2 Carbon Abstract Otp Authenticator with an average score of 4.3 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 4.30 |
It may take a day or so for new Wso2 Carbon Abstract Otp Authenticator vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Wso2 Carbon Abstract Otp Authenticator Security Vulnerabilities
WSO2 Identity Server PII Leak via OTP Tenant Isolation Flaw
CVE-2025-13909
4.3 - Medium
- August 06, 2026
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.
Information Disclosure
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Wso2 Carbon Abstract Otp Authenticator or by Wso2? Click the Watch button to subscribe.