Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions
Summary
| CVE | CVE-2025-12627 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:28 UTC |
| Updated | 2026-08-06 15:31:57 UTC |
| Description | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user. An attacker who gains access to an impersonated user's access token can exploit this weakness to renew their authorization. This results in the continued ability to perform actions on behalf of the actual user, compromising log integrity and traceability by masking the true actor. |
Risk And Classification
Primary CVSS: v3.1 2.4 LOW from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.001300000 probability, percentile 0.029840000 (date 2026-08-08)
Problem Types: CWE-613 | CWE-613 CWE-613: Insufficient Session Expiration
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 2.4 | LOW | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 2.4 | LOW | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 Identity Server | affected 7.0.0 7.0.0.130 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.1.0 7.1.0.38 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 7.0.26 7.0.26.83 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | affected 7.0.259 7.0.259.31 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon OAuth | unaffected x * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4619/#solution
There are currently no legacy QID mappings associated with this CVE.