CVE-2025-13909
Received Received - Intake

Authentication Bypass in Tenant Isolation via Email OTP

Vulnerability report for CVE-2025-13909, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wso2 identity_server From 7.1.0 (inc)
wso2 identity_server From 7.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows authentication requests without proper tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This can lead to exposure of personally identifiable information between different tenants.

Impact Analysis

An attacker could access user details like mobile numbers across different tenants, leading to privacy violations and potential unauthorized access to sensitive data.

Compliance Impact

This vulnerability may result in regulatory non-compliance due to unauthorized disclosure of personally identifiable information, potentially violating GDPR, HIPAA, and other privacy regulations.

Mitigation Strategies

Apply the public fixes provided by WSO2 via GitHub pull requests for affected components. Upgrade to the latest unaffected versions of WSO2 Identity Server (7.1.0 or 7.0.0). For WSO2 Support Subscription Holders, apply updates at version levels 42 (Identity Server 7.1.0) or 134 (Identity Server 7.0.0).

Disable Email OTP, SMS OTP, or Magic Link as first-factor authenticators in multi-tenant deployments until the fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-13909. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart