CVE-2025-13909

Summary

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information.

Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.

Affected Software

VendorProductVersion RangeStatus
WSO2WSO2 Identity Server7.0.0 < 7.0.0.134affected
WSO2WSO2 Identity Server7.1.0 < 7.1.0.42affected
WSO2WSO2 Carbon Identity Application Authentication Framework7.0.78 < 7.0.78.162affected
WSO2WSO2 Carbon Identity Application Authentication Framework7.8.23 < 7.8.23.66affected
WSO2WSO2 Carbon Identity Application Authentication Framework7.8.550 <= *unaffected
WSO2WSO2 Carbon MagicLink Authenticator Module1.1.22 < 1.1.22.6affected
WSO2WSO2 Carbon MagicLink Authenticator Module1.1.31 < 1.1.31.3affected
WSO2WSO2 Carbon MagicLink Authenticator Module1.1.45 <= *unaffected
WSO2WSO2 Carbon Abstract OTP Authenticator1.0.5 < 1.0.5.4affected
WSO2WSO2 Carbon Abstract OTP Authenticator1.0.10 < 1.0.10.1affected
WSO2WSO2 Carbon Abstract OTP Authenticator1.0.24 <= *unaffected
WSO2Email OTP Authenticator1.0.30 < 1.0.30.4affected
WSO2Email OTP Authenticator1.0.51 <= *unaffected

Weaknesses

  • CWE-200: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-20: CWE-20: Improper Input Validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References