Impact
The vulnerability, classified as CWE-20 and CWE-200, occurs when WSO2 Identity Server accepts authentication requests without sufficient validation to enforce tenant isolation for its Email OTP, SMS OTP, and Magic Link first‑factor authenticators. This flaw permits an attacker to retrieve personally identifiable information from users belonging to other tenants, including phone numbers, thereby violating privacy and potentially breaching regulatory obligations.
Affected Systems
Affected products include WSO2 Email OTP Authenticator, WSO2 Carbon Abstract OTP Authenticator, WSO2 Carbon Identity Application Authentication Framework, WSO2 Carbon MagicLink Authenticator Module, and WSO2 Identity Server. No specific version range has been disclosed in the advisory, so all installed instances of these components should be evaluated for the presence of the flaw.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. EPSS is not available, and the issue is not listed in CISA KEV, suggesting limited current exploitation activity. The likely attack vector involves a remote attacker submitting crafted authentication requests to the affected authenticator endpoints. Successful exploitation leads to disclosure of PII across tenants and carries privacy and compliance risks. Immediate remediation using the official solution is recommended to prevent potential data exposure.
OpenCVE Enrichment