Impact
The vulnerability lies in WSO2 Identity Server’s user impersonation flow, which fails to restrict the use of refresh tokens for impersonated sessions. An attacker who has already obtained an access token for an impersonated user can invoke the refresh token grant to receive new access tokens, thereby extending the window of unauthorized actions. While the CVSS score of 2.4 indicates a low overall severity, the flaw compromises log integrity and traceability, masking the true actor behind continued actions.
Affected Systems
The flaw affects all versions of WSO2 Carbon OAuth and WSO2 Identity Server. No specific version information is provided, so all releases should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 2.4 and the absence of EPSS data suggest a low likelihood of widespread exploitation, and the flaw is not listed in CISA’s KEV catalog. However, if an attacker can acquire an impersonated user’s access token, they can repeatedly renew it via the refresh token grant. The attack vector is a legitimate OAuth flow that does not require elevated privileges beyond the impersonated credential, making the vulnerability exploitable in environments where user impersonation is enabled and tokens are not tightly controlled.
OpenCVE Enrichment