Description
Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts.

The security consequence is that a locked user account can maintain access to protected resources through the use of existing, unexpired access tokens. This creates a security gap where access control policies are bypassed, potentially leading to unauthorized data access or actions until the tokens naturally expire.
Published: 2026-04-16
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Persistent Tokens
Action: Apply Patch
AI Analysis

Impact

Active access tokens are not revoked when a user account is locked in WSO2 Identity Server. This flaw allows previously issued, unexpired tokens to remain valid after the account is locked, creating a security gap where the locked account can continue to access protected resources. The vulnerability results in unauthorized access and a breach of access‑control policies until the tokens naturally expire, as defined by CWE‑613.

Affected Systems

The flaw affects WSO2 Identity Server. No specific version range is listed in the advisory, so all versions of the product are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score is 6, indicating a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The attack path is inferred to rely on an account that already holds a valid token; after the account is locked, an attacker can continue to use that token until it expires. The issue is exploitable in any environment where users or administrators can lock accounts and there is no automatic token revocation policy in place.

Generated by OpenCVE AI on April 17, 2026 at 03:26 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4684/#solution


OpenCVE Recommended Actions

  • Follow the vendor‑advised procedure at https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4684/#solution to apply the latest patch or configuration changes that enforce token revocation on account lock.
  • Verify token revocation by locking a test account and attempting to use an active token associated with that account; the request should be denied.
  • Review existing tokens in the identity server, identify any tokens belonging to locked accounts, and revoke them manually or via a cleanup script.

Generated by OpenCVE AI on April 17, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Apr 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 identity Server
Vendors & Products Wso2 identity Server

Thu, 16 Apr 2026 10:45:00 +0000

Type Values Removed Values Added
Description Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts. The security consequence is that a locked user account can maintain access to protected resources through the use of existing, unexpired access tokens. This creates a security gap where access control policies are bypassed, potentially leading to unauthorized data access or actions until the tokens naturally expire.
Title Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock
First Time appeared Wso2
Wso2 wso2 Identity Server
Weaknesses CWE-613
CPEs cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Identity Server
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Wso2 Identity Server Wso2 Identity Server
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-04-16T12:30:14.886Z

Reserved: 2025-11-03T06:20:27.950Z

Link: CVE-2025-12624

cve-icon Vulnrichment

Updated: 2026-04-16T12:19:52.974Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-16T11:16:26.447

Modified: 2026-04-17T15:38:09.243

Link: CVE-2025-12624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T03:30:08Z

Weaknesses