When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.
History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.
Title Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges
First Time appeared Wso2
Wso2 wso2 Enterprise Integrator
Wso2 wso2 Identity Server
Weaknesses CWE-613
CPEs cpe:2.3:a:wso2:wso2_enterprise_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Enterprise Integrator
Wso2 wso2 Identity Server
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-06T17:32:05.058Z

Reserved: 2025-10-27T07:42:13.579Z

Link: CVE-2025-12317

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:00:05Z