Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure
Summary
| CVE | CVE-2025-13909 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:28 UTC |
| Updated | 2026-08-10 14:15:12 UTC |
| Description | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.002010000 probability, percentile 0.101250000 (date 2026-08-09)
Problem Types: CWE-20 | CWE-200 | CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | CWE-20 CWE-20: Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | CVSS | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wso2 | Identity Server | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 Identity Server | affected 7.0.0 7.0.0.134 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.1.0 7.1.0.42 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 7.0.78 7.0.78.162 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 7.8.23 7.8.23.66 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | unaffected 7.8.550 * custom | Not specified |
| CNA | WSO2 | WSO2 Carbon MagicLink Authenticator Module | affected 1.1.22 1.1.22.6 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon MagicLink Authenticator Module | affected 1.1.31 1.1.31.3 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon MagicLink Authenticator Module | unaffected 1.1.45 * custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Abstract OTP Authenticator | affected 1.0.5 1.0.5.4 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Abstract OTP Authenticator | affected 1.0.10 1.0.10.1 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Abstract OTP Authenticator | unaffected 1.0.24 * custom | Not specified |
| CNA | WSO2 | Email OTP Authenticator | affected 1.0.30 1.0.30.4 custom | Not specified |
| CNA | WSO2 | Email OTP Authenticator | unaffected 1.0.51 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4731/#solution
There are currently no legacy QID mappings associated with this CVE.