Description
Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations. A malicious actor with privileges to configure adaptive authentication within one organization can leverage this functionality to execute authentication logic on other organizations and sub-organizations.

This flaw allows bypassing authorization boundaries between organizations, leading to unauthorized access to critical operations and user accounts in other organizations. When adaptive authentication is enabled in a multi-organization deployment, a malicious actor with privileges to configure adaptive authentication in one organization could exploit this feature to perform critical operations in other organizations without authorization. This may result in privilege escalation, unauthorized access to resources, and potential account takeover across organizations.
Published: 2026-05-11
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because the WSO2 Identity Server does not validate the organization context during adaptive authentication flows, a weakness identified as CWE‑284 and CWE‑863. As a result, a user who has permission to configure adaptive authentication in one organization can trigger authentication logic that is intended for other organizations. This allows the attacker to bypass authorization boundaries, gaining unauthorized access to sensitive operations, user accounts, and potentially taking ownership of accounts across multiple organizations. The impact is a significant escalation of privileges for the attacker within a multi-organization deployment.

Affected Systems

WSO2 products affected include the Conditional Authentication User and Roles Related Functions component and the core WSO2 Identity Server. The vulnerability applies to all versions of these components that handle adaptive authentication without context validation; specific version details are not disclosed in the advisory.

Risk and Exploitability

The CVSS score of 6.4 places this flaw in the medium severity range. The EPSS score of less than 1% indicates a low probability of exploitation at present, and it is not listed in the CISA KEV catalog, suggesting no known active exploitation. However, the attack vector involves configuration privileges within an organization; an attacker who can modify adaptive authentication policies can activate the exploit locally within the same deployment. The grant of such privileges is a prerequisite, so the scope is limited to systems where this administrative authority exists. Once triggered, the attacker gains far‑beyond the intended authorization boundaries, potentially accessing all resources in target organizations.

Generated by OpenCVE AI on May 11, 2026 at 23:08 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4530/#solution


OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade as instructed at the solution link provided by WSO2
  • If a patch is not yet available, restrict the ability to configure adaptive authentication to trusted administrators only and review the organization context checks in custom adaptive authentication workflows
  • Disable or remove adaptive authentication for any organization that does not require it, and implement strict access controls so that only designated organizations can be targeted

Generated by OpenCVE AI on May 11, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 11 May 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 11 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 identity Server
Weaknesses CWE-285
Vendors & Products Wso2 identity Server

Mon, 11 May 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 11 May 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 11 May 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 11 May 2026 15:15:00 +0000

Type Values Removed Values Added
Description Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations. A malicious actor with privileges to configure adaptive authentication within one organization can leverage this functionality to execute authentication logic on other organizations and sub-organizations. This flaw allows bypassing authorization boundaries between organizations, leading to unauthorized access to critical operations and user accounts in other organizations. When adaptive authentication is enabled in a multi-organization deployment, a malicious actor with privileges to configure adaptive authentication in one organization could exploit this feature to perform critical operations in other organizations without authorization. This may result in privilege escalation, unauthorized access to resources, and potential account takeover across organizations.
Title Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover
First Time appeared Wso2
Wso2 conditional Authentication User And Roles Related Functions
Wso2 wso2 Identity Server
CPEs cpe:2.3:a:wso2:conditional_authentication_user_and_roles_related_functions:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 conditional Authentication User And Roles Related Functions
Wso2 wso2 Identity Server
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Wso2 Conditional Authentication User And Roles Related Functions Identity Server Wso2 Identity Server
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-05-11T15:18:59.783Z

Reserved: 2025-09-04T08:21:53.892Z

Link: CVE-2025-9973

cve-icon Vulnrichment

Updated: 2026-05-11T15:18:55.664Z

cve-icon NVD

Status : Received

Published: 2026-05-11T12:16:11.050

Modified: 2026-05-11T16:17:29.377

Link: CVE-2025-9973

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-11T23:15:09Z

Weaknesses