When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user.
This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire. | |
| Title | Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges | |
| First Time appeared |
Wso2
Wso2 wso2 Enterprise Integrator Wso2 wso2 Identity Server |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:wso2:wso2_enterprise_integrator:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2 Enterprise Integrator Wso2 wso2 Identity Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-08-06T17:32:05.058Z
Reserved: 2025-10-27T07:42:13.579Z
Link: CVE-2025-12317
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T01:00:05Z