This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.
Project Subscriptions
No advisories yet.
Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4672/#solution
Workaround
No workaround given by the vendor.
Fri, 07 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Aug 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wso2 enterprise Integrator
Wso2 identity Server |
|
| Vendors & Products |
Wso2 enterprise Integrator
Wso2 identity Server |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire. | |
| Title | Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges | |
| First Time appeared |
Wso2
Wso2 wso2 Enterprise Integrator Wso2 wso2 Identity Server |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:wso2:wso2_enterprise_integrator:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2 Enterprise Integrator Wso2 wso2 Identity Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-08-07T17:49:16.891Z
Reserved: 2025-10-27T07:42:13.579Z
Link: CVE-2025-12317
Updated: 2026-08-07T17:49:08.322Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T03:15:03Z