Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-9973— Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover

CVSS 6.4 · Medium EPSS 0.02% · P6

Affected Version Matrix 3

VendorProductVersion RangeStatus
WSO2Conditional Authentication User and Roles Related Functions1.2.76< 1.2.76.1affected
1.2.82≤ *unaffected
WSO2WSO2 Identity Server7.1.0< 7.1.0.26affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-9973

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover
Source: NVD (National Vulnerability Database)
Vulnerability Description
Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations. A malicious actor with privileges to configure adaptive authentication within one organization can leverage this functionality to execute authentication logic on other organizations and sub-organizations. This flaw allows bypassing authorization boundaries between organizations, leading to unauthorized access to critical operations and user accounts in other organizations. When adaptive authentication is enabled in a multi-organization deployment, a malicious actor with privileges to configure adaptive authentication in one organization could exploit this feature to perform critical operations in other organizations without authorization. This may result in privilege escalation, unauthorized access to resources, and potential account takeover across organizations.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
WSO2 Identity Server 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WSO2 Identity Server(IS)是美国WSO2公司的一款身份认证服务器。 WSO2 Identity Server存在访问控制错误漏洞,该漏洞源于在执行自适应认证流程时未验证组织上下文,可能导致具有配置权限的攻击者在多组织部署中跨组织执行认证逻辑,绕过授权边界,导致权限提升和账户接管。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
WSO2WSO2 Identity Server 7.1.0 ~ 7.1.0.26 -
WSO2Conditional Authentication User and Roles Related Functions 1.2.76 ~ 1.2.76.1 -

II. Public POCs for CVE-2025-9973

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-9973

登录查看更多情报信息。

Same Patch Batch · WSO2 · 2026-05-11 · 6 CVEs total

CVE-2025-104708.6 HIGHDenial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Una
CVE-2025-83256.3 MEDIUMImproper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Oper
CVE-2024-03915.3 MEDIUMUsername Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Disc
CVE-2025-81545.3 MEDIUMHTTP Header Injection via Webhook API in Multiple WSO2 Products Allows Response Header Man
CVE-2025-10908Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allo

IV. Related Vulnerabilities

V. Comments for CVE-2025-9973

No comments yet


Leave a comment