CVE-2025-12627
Received Received - Intake

Session Hijacking via Refresh Token in WSO2 Identity Server

Vulnerability report for CVE-2025-12627, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user. An attacker who gains access to an impersonated user's access token can exploit this weakness to renew their authorization. This results in the continued ability to perform actions on behalf of the actual user, compromising log integrity and traceability by masking the true actor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wso2 identity_server 7.1.0
wso2 identity_server 7.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects WSO2 Identity Server's user impersonation flow. It fails to properly manage refresh tokens for impersonated sessions. An attacker with an access token for an impersonated user can use the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user. This masks the true actor in logs and compromises traceability.

Detection Guidance

Detecting this vulnerability requires checking WSO2 Identity Server logs for unusual refresh token grants during impersonated sessions. Look for repeated token renewal requests from the same user account that may indicate unauthorized access. Review logs for any access tokens issued outside normal user sessions.

Impact Analysis

If exploited, an attacker could maintain unauthorized access to a user's account by renewing tokens, allowing them to perform actions while appearing as the legitimate user. This could lead to unauthorized data access, actions taken on behalf of the user, and compromised log integrity.

Compliance Impact

This vulnerability could impact compliance by obscuring the true actor in logs, making it difficult to track actions for audit purposes. This may violate requirements for accountability and traceability in GDPR and HIPAA, where clear logging and user activity tracking are essential.

Mitigation Strategies

Apply the provided GitHub pull request fixes or update to WSO2 Identity Server versions 7.1.0 (update 38) or 7.0.0 (update 130). If using a subscription, ensure the specified updates are installed. Monitor logs for suspicious token renewal activities and revoke any potentially compromised tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-12627. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart