Description
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user.

Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.
Published: 2026-07-04
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the silent Just‑In‑Time provisioning feature of several WSO2 products allows a federated identity provider to override the role assignments of a local user when the federated user shares the same username. The provisioning process does not isolate the two sets of roles, so the account’s local roles are replaced by the roles defined in the federated IDP. The overwrite is limited to the roles that the federated provider grants, which usually confers minimal access unless the provider is configured with elevated permissions. Consequently, an attacker who can act as the federated provider and knows a valid local username may elevate their privileges within the affected system, but the scope is confined to the specific user account. The vulnerability requires a federated IDP with silent JIT provisioning enabled and an attacker’s knowledge of a matching local username. It is not an arbitrary code execution or cross‑site scripting flaw; instead it is an identity and access control in the local user’s role assignments being replaced, potentially granting the attacker higher authority. Because the CVSS base score is 4.8 and the EPSS score is < 1%, the likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. Exploitation is a deliberate, out‑of‑band attack that depends on the presence of a federated IDP and the existence of a username collision.

Affected Systems

WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, and WSO2 Open Banking IAM are affected. Version information was not detailed in the advisory, so any released version of these products may be vulnerable pending a patch from WSO2.

Risk and Exploitability

The CVSS score of 4.8 and the EPSS score of < 1% indicate a low likelihood of exploitation. The vulnerability is not catalogued in CISA KEV. Exploitation requires an IDP with silent Just‑In‑Time provisioning enabled and an attacker’s knowledge of a matching local username; it is therefore an out‑of‑band attack that can modify a local account’s roles but does not grant arbitrary code execution. The impact is confined to the privileges of the affected account, though it may allow a malicious user to acquire higher authority than originally intended.

Generated by OpenCVE AI on July 26, 2026 at 21:42 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3179/#solution


OpenCVE Recommended Actions

  • Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3179/#solution
  • Disable silent JIT provisioning for corporate identity providers or configure role mapping rules to prevent role overwriting
  • Enforce unique usernames or maintain separate namespaces for local and federated users to avoid username collisions
  • Regularly audit local user role assignments after provisioning events to detect unintended changes

Generated by OpenCVE AI on July 26, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2
Wso2 wso2 Api Manager
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam
Vendors & Products Wso2
Wso2 wso2 Api Manager
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam

Sat, 04 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.
Title Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation
Weaknesses CWE-298
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Wso2 Wso2 Api Manager Wso2 Identity Server Wso2 Identity Server As Key Manager Wso2 Open Banking Am Wso2 Open Banking Iam
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-07-06T13:50:13.770Z

Reserved: 2024-02-06T04:46:46.449Z

Link: CVE-2024-1248

cve-icon Vulnrichment

Updated: 2026-07-06T13:50:09.509Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T21:45:05Z

Weaknesses
  • CWE-298

    Improper Validation of Certificate Expiration