Impact
A flaw in the implicit-association resolver incorrectly initializes from a secondary user store and skips checks against the primary store during lookup and uniqueness validation. This can incorrectly bind a subject to an unintended local account when the same lookup claim, such as a username or e‑mail address, exists in both stores. The resulting identity confusion may allow an attacker to gain access to an account with fewer privileges or hamper legitimate users from linking their external Identity Provider account, potentially leading to unauthorized access or denied service.
Affected Systems
The vulnerability affects WSO2 Token Exchange Grant Type for OAuth and WSO2 Identity Server when a secondary user store is configured. Version information was not specified in the CNA data, meaning any installation that uses secondary stores is potentially impacted. Deployments that do not configure secondary stores, disable implicit association, or enforce globally unique claim values are not affected.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability rates as low‑to‑medium severity, and the EPSS score is not available. It is also not listed in the CISA KEV catalog. Exploitation requires an environment configured with secondary user stores and an external Identity Provider that supplies duplicate claim values. The attack vector is therefore an indirect configuration-based weakness rather than an active exploitation surface; however, the impact on account integrity warrants prompt remediation.
OpenCVE Enrichment