When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.
History

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 enterprise Integrator
Wso2 identity Server
Vendors & Products Wso2 enterprise Integrator
Wso2 identity Server

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.
Title Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges
First Time appeared Wso2
Wso2 wso2 Enterprise Integrator
Wso2 wso2 Identity Server
Weaknesses CWE-613
CPEs cpe:2.3:a:wso2:wso2_enterprise_integrator:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Enterprise Integrator
Wso2 wso2 Identity Server
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-07T17:49:16.891Z

Reserved: 2025-10-27T07:42:13.579Z

Link: CVE-2025-12317

cve-icon Vulnrichment

Updated: 2026-08-07T17:49:08.322Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T03:15:03Z