Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
Summary
| CVE | CVE-2024-8995 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:27 UTC |
| Updated | 2026-08-13 13:18:42 UTC |
| Description | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code. |
Risk And Classification
Primary CVSS: v3.1 4.9 MEDIUM from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
EPSS: 0.001190000 probability, percentile 0.020790000 (date 2026-08-09)
Problem Types: CWE-613 | CWE-613 CWE-613: Insufficient Session Expiration
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 4.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N |
| 3.1 | CNA | CVSS | 4.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wso2 | Api Control Plane | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 API Manager | unknown 3.1.0 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.1.0 3.1.0.320 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.2.0 3.2.0.413 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.2.1 3.2.1.90 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.0.0 4.0.0.334 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.1.0 4.1.0.255 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.2.0 4.2.0.195 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.3.0 4.3.0.106 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.4.0 4.4.0.70 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.5.0 4.5.0.55 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.6.0 4.6.0.19 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.5.0 4.5.0.54 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.6.0 4.6.0.19 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.5.0 4.5.0.56 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.6.0 4.6.0.20 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.5.0 4.5.0.55 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.6.0 4.6.0.19 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking AM | unknown 2.0.0 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking AM | affected 2.0.0 2.0.0.369 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | unknown 5.10.0 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.10.0 5.10.0.345 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.11.0 5.11.0.395 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 6.0.0 6.0.0.229 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 6.1.0 6.1.0.208 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking IAM | unknown 2.0.0 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking IAM | affected 2.0.0 2.0.0.389 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | unknown 5.10.0 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | affected 5.10.0 5.10.0.338 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.4.2 6.4.2.154 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.4.111 6.4.111.131 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.4.176 6.4.176.35 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.4.180 6.4.180.17 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.8.0 6.8.0.46 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.9.6 6.9.6.34 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.11.21 6.11.21.59 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.13.16 6.13.16.27 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.13.19 6.13.19.19 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.13.27 6.13.27.15 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 6.13.41 6.13.41.4 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | unaffected 6.11.53 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-2753/#solution
There are currently no legacy QID mappings associated with this CVE.