Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-9973— Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover

Quick assessment

Affected
WSO2 WSO2 Identity Server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WSO2 Identity Server(IS)是美国WSO2公司的一款身份认证服务器。 WSO2 Identity Server存在访问控制错误漏洞,该漏洞源于在执行自适应认证流程时未验证组织上下文,可能导致具有配置权限的攻击者在多组织部署中跨组织执行认证逻辑,绕过授权边界,导致权限提升和账户接管。

CVSS 6.4 · Medium EPSS 0.37% · P28

Affected Version Matrix 3

VendorProduct Version RangeStatus
WSO2 Conditional Authentication User and Roles Related Functions 1.2.76< 1.2.76.1 affected
1.2.82≤ * unaffected
WSO2 WSO2 Identity Server 7.1.0< 7.1.0.26 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-9973

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover
Source: CVE Program / CVE List V5
Vulnerability Description
Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations. A malicious actor with privileges to configure adaptive authentication within one organization can leverage this functionality to execute authentication logic on other organizations and sub-organizations. This flaw allows bypassing authorization boundaries between organizations, leading to unauthorized access to critical operations and user accounts in other organizations. When adaptive authentication is enabled in a multi-organization deployment, a malicious actor with privileges to configure adaptive authentication in one organization could exploit this feature to perform critical operations in other organizations without authorization. This may result in privilege escalation, unauthorized access to resources, and potential account takeover across organizations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
WSO2 Identity Server 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WSO2 Identity Server(IS)是美国WSO2公司的一款身份认证服务器。 WSO2 Identity Server存在访问控制错误漏洞,该漏洞源于在执行自适应认证流程时未验证组织上下文,可能导致具有配置权限的攻击者在多组织部署中跨组织执行认证逻辑,绕过授权边界,导致权限提升和账户接管。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
WSO2 WSO2 Identity Server 7.1.0 ~ 7.1.0.26 -
WSO2 Conditional Authentication User and Roles Related Functions 1.2.76 ~ 1.2.76.1 -

II. Public POCs for CVE-2025-9973

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-9973

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-9973 (1)

Same Patch Batch · WSO2 · 2026-05-11 · 6 CVEs total

CVE-2025-10470 8.6 HIGH Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Una
CVE-2025-8325 6.3 MEDIUM Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Oper
CVE-2024-0391 5.3 MEDIUM Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Disc
CVE-2025-8154 5.3 MEDIUM HTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Man
CVE-2025-10908 Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allo

IV. Related Vulnerabilities

V. Comments for CVE-2025-9973

No comments yet


Leave a comment