CVE-2024-8995
Received Received - Intake

Authorization Code Reuse in System After User Deletion

Vulnerability report for CVE-2024-8995, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
wso2 api_control_plane *
wso2 api_manager *
wso2 identity_server *
wso2 open_banking_am *
wso2 open_banking_iam *
wso2 traffic_manager *
wso2 universal_gateway *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves unused authorization codes for deleted users not being invalidated. Attackers with the authorization code and client credentials can reuse these codes to obtain access tokens, gaining unauthorized access to sensitive resources based on the original scopes.

Impact Analysis

If exploited, this vulnerability could allow unauthorized access to your systems or data. Attackers might impersonate deleted users to gain access to resources they were previously authorized for, depending on the scope of the original authorization.

Mitigation Strategies

Apply the provided fixes or update to the latest unaffected versions of the affected WSO2 products. WSO2 Support Subscription Holders should apply specific update levels to address the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-8995. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart