CVE-2025-12317
Received Received - Intake

Authentication Token Persistence in WSO2 After Role Removal

Vulnerability report for CVE-2025-12317, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wso2 wso2 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the WSO2 product occurs when a user's internal roles are removed but the system does not invalidate their previously issued authentication tokens. This means the user retains access privileges even after role revocation, potentially allowing unauthorized actions or access to restricted resources until tokens expire.

Impact Analysis

If you are a WSO2 user or administrator, this vulnerability could allow former users or compromised accounts to maintain unauthorized access to sensitive systems or data. It undermines role-based access control and could lead to data breaches or privilege escalation until tokens naturally expire.

Compliance Impact

This vulnerability may violate compliance requirements such as GDPR's data protection principles or HIPAA's access control mandates, as it allows unauthorized access to sensitive data. Organizations using WSO2 must address this to maintain regulatory compliance and avoid potential penalties.

Mitigation Strategies

Immediately revoke all active authentication tokens for users whose roles have been removed. Review and rotate any compromised or exposed credentials. Monitor user access logs for unusual activity after role revocations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-12317. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart