CVE-2025-14779
Received Received - Intake

Secret Type Deletion Flaw in REST API

Vulnerability report for CVE-2025-14779, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations. Exploitation of this vulnerability can result in the unintended deletion of secrets across the entire deployment, potentially causing configuration failures, service interruptions, and a denial-of-service condition. This vulnerability requires delete permissions for the Secret Type Management REST API, which are by default only granted to administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
wso2 identity_server 7.1.0
wso2 identity_server 6.1.0
wso2 identity_server 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-281 The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Secret Type Management REST API failing to properly isolate access controls when deleting a secret type. The system incorrectly removes secrets associated with that type across all organizations instead of just the intended one. This can cause unintended deletion of secrets, configuration failures, service interruptions, and denial-of-service conditions.

Impact Analysis

If exploited, this vulnerability can lead to the unintended deletion of secrets across your entire deployment. This may cause configuration failures, service interruptions, and a denial-of-service condition. Exploitation requires delete permissions for the Secret Type Management REST API, which are typically only granted to administrators.

Mitigation Strategies
  • Apply the fix from the public pull request at https://github.com/wso2/carbon-identity-framework/pull/7434 or update to the latest unaffected version.
  • For WSO2 Support Subscription Holders, apply the specific update levels available for each affected version.
  • After applying the fix, modify the deployment.toml file to enable the Secret Type Management REST API fix, as it is disabled by default post-update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14779. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart