Wso2 Carbon Identity Application Authentication Framework Wso2 Carbon Identity Application Authentication Framework

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Wso2 Carbon Identity Application Authentication Framework.

By the Year

In 2026 there have been 2 vulnerabilities in Wso2 Carbon Identity Application Authentication Framework with an average score of 6.9 out of ten.

Year Vulnerabilities Average Score
2026 2 6.85

It may take a day or so for new Wso2 Carbon Identity Application Authentication Framework vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wso2 Carbon Identity Application Authentication Framework Security Vulnerabilities

WSO2 IDS Auth Flow Bypass via Conditional Auth Script
CVE-2025-15039 9.4 - Critical - August 06, 2026

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Protection Mechanism Failure

WSO2 Identity Server PII Leak via OTP Tenant Isolation Flaw
CVE-2025-13909 4.3 - Medium - August 06, 2026

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.

Information Disclosure

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Wso2 Carbon Identity Application Authentication Framework or by Wso2? Click the Watch button to subscribe.

Wso2
Vendor

subscribe