Impact
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This flaw permits the user to retain the privileges tied to those tokens, enabling continued access to APIs, services, or data that should be restricted after role removal. The vulnerability, described by CWE‑613, allows an attacker who controls a user account to perform unauthorized actions or access restricted resources until the tokens naturally expire.
Affected Systems
The flaw affects WSO2 Enterprise Integrator and WSO2 Identity Server. No specific affected versions are disclosed in the advisory, so any installation of these products that includes the described token handling logic is potentially vulnerable.
Risk and Exploitability
Assigning a CVSS score of 5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so evidence of widespread exploitation is lacking. Attackers would need legitimate removal of roles for a target user or another authorization to trigger the scenario; once that occurs, the old token remains valid and grants the compromised privileges until expiration.
OpenCVE Enrichment