Impact
A flaw in the silent Just‑In‑Time provisioning feature of several WSO2 products allows a federated identity provider to override the role assignments of a local user when the federated user shares the same username. The provisioning process does not isolate the two sets of roles, so the account’s local roles are replaced by the roles defined in the federated IDP. The overwrite is limited to the roles that the federated provider grants, which usually confers minimal access unless the provider is configured with elevated permissions. Consequently, an attacker who can act as the federated provider and knows a valid local username may elevate their privileges within the affected system, but the scope is confined to the specific user account. The vulnerability requires a federated IDP with silent JIT provisioning enabled and an attacker’s knowledge of a matching local username. It is not an arbitrary code execution or cross‑site scripting flaw; instead it is an identity and access control in the local user’s role assignments being replaced, potentially granting the attacker higher authority. Because the CVSS base score is 4.8 and the EPSS score is < 1%, the likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. Exploitation is a deliberate, out‑of‑band attack that depends on the presence of a federated IDP and the existence of a username collision.
Affected Systems
WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, and WSO2 Open Banking IAM are affected. Version information was not detailed in the advisory, so any released version of these products may be vulnerable pending a patch from WSO2.
Risk and Exploitability
The CVSS score of 4.8 and the EPSS score of < 1% indicate a low likelihood of exploitation. The vulnerability is not catalogued in CISA KEV. Exploitation requires an IDP with silent Just‑In‑Time provisioning enabled and an attacker’s knowledge of a matching local username; it is therefore an out‑of‑band attack that can modify a local account’s roles but does not grant arbitrary code execution. The impact is confined to the privileges of the affected account, though it may allow a malicious user to acquire higher authority than originally intended.
OpenCVE Enrichment