Description
The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious actors to conduct brute force attacks by repeatedly guessing the OTP.

The absence of automatic expiration for OTPs grants attackers an unlimited timeframe to attempt guessing the correct code. A successful brute force attack can lead to an MFA bypass, resulting in the unauthorized takeover of a user's account and compromising the security and privacy of both the individual and the system.
Published: 2026-10-08
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: MFA bypass that can lead to unauthorized account takeover and privacy breach
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in WSO2 Identity Server permits OTPs used in MFA to remain valid indefinitely, allowing attackers to repeat OTP guesses without time constraints. This missing expiration enables brute force attempts that can ultimately bypass MFA, leading to unauthorized account takeover and compromising user privacy and system integrity. The weakness is identified as CWE-613, indicating a failure to enforce proper authentication controls.

Affected Systems

WSO2 Identity Server is the impacted product. The advisory covers the default WSO2 Identity Server deployment, with no specific version list provided in the CNA data. Administrators should verify that their installation uses a version affected by this issue.

Risk and Exploitability

The CVSS base score of 5.9 indicates moderate severity. EPSS score is not available, so current exploitation probability cannot be quantified, and the vulnerability is not currently in the CISA KEV list. Attackers can exploit the lack of OTP expiration through indefinite brute force attempts, requiring only the ability to send or intercept SMS codes. The vulnerability is remote and does not depend on privileged local access. Because the OTP remains valid indefinitely, the window for a successful exploitation is effectively unlimited, increasing the risk of compromise.

Generated by OpenCVE AI on October 8, 2026 at 02:25 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3149/#solution


OpenCVE Recommended Actions

  • Apply the vendor-published patch for WSO2 Identity Server as directed at the advisory page.
  • Configure an OTP expiration timeout (e.g., 5 minutes) in the MFA settings to enforce automatic expiration.
  • Disable or restrict usage of SMS OTPs for noncritical authentication flows until the patch is applied.
  • Enable logging and monitoring for repeated OTP requests and block IPs or accounts exhibiting abnormal activity.

Generated by OpenCVE AI on October 8, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 01:15:00 +0000

Type Values Removed Values Added
Description The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious actors to conduct brute force attacks by repeatedly guessing the OTP. The absence of automatic expiration for OTPs grants attackers an unlimited timeframe to attempt guessing the correct code. A successful brute force attack can lead to an MFA bypass, resulting in the unauthorized takeover of a user's account and compromising the security and privacy of both the individual and the system.
Title Potential brute force vulnerability due to non-expiring SMS OTPs
First Time appeared Wso2
Wso2 wso2 Identity Server
Weaknesses CWE-613
CPEs cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Identity Server
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wso2 Wso2 Identity Server
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-10-08T17:13:45.357Z

Reserved: 2024-08-23T14:52:53.493Z

Link: CVE-2024-8122

cve-icon Vulnrichment

Updated: 2026-10-08T17:13:36.690Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T01:16:32.037

Modified: 2026-10-08T17:17:10.723

Link: CVE-2024-8122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T02:30:06Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration