When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user.

This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.

Project Subscriptions

Vendors Products
Enterprise Integrator Subscribe
Identity Server Subscribe
Wso2 Enterprise Integrator Subscribe
Wso2 Identity Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4672/#solution


Workaround

No workaround given by the vendor.

History

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 enterprise Integrator
Wso2 identity Server
Vendors & Products Wso2 enterprise Integrator
Wso2 identity Server

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.
Title Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges
First Time appeared Wso2
Wso2 wso2 Enterprise Integrator
Wso2 wso2 Identity Server
Weaknesses CWE-613
CPEs cpe:2.3:a:wso2:wso2_enterprise_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Enterprise Integrator
Wso2 wso2 Identity Server
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-07T17:49:16.891Z

Reserved: 2025-10-27T07:42:13.579Z

Link: CVE-2025-12317

cve-icon Vulnrichment

Updated: 2026-08-07T17:49:08.322Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T03:15:03Z

Weaknesses