Improper Access Control via Secret Type Management API in WSO2 Identity Server
Summary
| CVE | CVE-2025-14779 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:28 UTC |
| Updated | 2026-08-10 14:03:28 UTC |
| Description | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations. Exploitation of this vulnerability can result in the unintended deletion of secrets across the entire deployment, potentially causing configuration failures, service interruptions, and a denial-of-service condition. This vulnerability requires delete permissions for the Secret Type Management REST API, which are by default only granted to administrators. |
Risk And Classification
Primary CVSS: v3.1 3.8 LOW from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
EPSS: 0.001880000 probability, percentile 0.085660000 (date 2026-08-09)
Problem Types: CWE-281 | CWE-281 CWE-281: Assigning Permissions Instead of Checking Them
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 3.8 | LOW | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L |
| 3.1 | CNA | CVSS | 3.8 | LOW | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
LowCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wso2 | Identity Server | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 Identity Server | affected 6.0.0 6.0.0.261 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 6.1.0 6.1.0.262 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.1.0 7.1.0.46 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity API Server Secret Management Common | affected 1.2.3 1.2.3.7 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity API Server Secret Management Common | affected 1.2.23 1.2.23.11 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity API Server Secret Management Common | affected 1.3.83 1.3.83.16 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity API Server Secret Management Common | unaffected 7.8.521 * custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity API Server Secret Management V1 | affected 1.2.3 1.2.3.7 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity API Server Secret Management V1 | affected 1.2.23 1.2.23.11 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity API Server Secret Management V1 | affected 1.3.83 1.3.83.16 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity API Server Secret Management V1 | unaffected 7.8.521 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4597/#solution
There are currently no legacy QID mappings associated with this CVE.