Impact
The Secret Type Management REST API fails to enforce organizational boundaries when a secret type is deleted, allowing a single delete operation to remove all secrets of that type across every organization. This improper access control can cause configuration failures, interrupt services, and result in a denial‑of‑service condition. The vulnerability requires delete permissions that are normally granted only to administrators, limiting the attack surface to privileged users or internal actors with compromised credentials.
Affected Systems
Impact is limited to deployments of WSO2 Carbon Identity API Server Secret Management Common, WSO2 Carbon Identity API Server Secret Management V1, and WSO2 Identity Server. No specific product versions are listed; the issue applies to all until the vendor releases a fix.
Risk and Exploitability
The CVSS score is 3.8, indicating a low‑to‑moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the API delete permission is restricted to administrators, exploitation would require privileged access or internal compromise, making the likelihood of exploitation relatively low. However, any successful execution would compromise the integrity and availability of secrets across the entire deployment, presenting a moderate operational risk.
OpenCVE Enrichment