Wso2 Carbon Identity Api Server Secret Management V1 Wso2 Carbon Identity Api Server Secret Management V1

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Wso2 Carbon Identity Api Server Secret Management V1.

By the Year

In 2026 there have been 1 vulnerability in Wso2 Carbon Identity Api Server Secret Management V1 with an average score of 3.8 out of ten.

Year Vulnerabilities Average Score
2026 1 3.80

It may take a day or so for new Wso2 Carbon Identity Api Server Secret Management V1 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wso2 Carbon Identity Api Server Secret Management V1 Security Vulnerabilities

WSO2 Identity Server: Secret Type CM Cascade Deletes Across Org
CVE-2025-14779 3.8 - Low - August 06, 2026

The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations. Exploitation of this vulnerability can result in the unintended deletion of secrets across the entire deployment, potentially causing configuration failures, service interruptions, and a denial-of-service condition. This vulnerability requires delete permissions for the Secret Type Management REST API, which are by default only granted to administrators.

Improper Preservation of Permissions

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Wso2 Carbon Identity Api Server Secret Management V1 or by Wso2? Click the Watch button to subscribe.

Wso2
Vendor

subscribe