CVE-2024-8995 PUBLISHED

Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access

Assigner: WSO2
Reserved: 19.09.2024 Published: 06.08.2026 Updated: 06.08.2026

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused.

If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS Score: 4.9

Product Status

Vendor WSO2
Product WSO2 API Manager
Versions Default: unaffected
  • unknown from 0 to 3.1.0 (excl.)
  • affected from 3.1.0 to 3.1.0.320 (excl.)
  • affected from 3.2.0 to 3.2.0.413 (excl.)
  • affected from 3.2.1 to 3.2.1.90 (excl.)
  • affected from 4.0.0 to 4.0.0.334 (excl.)
  • affected from 4.1.0 to 4.1.0.255 (excl.)
  • affected from 4.2.0 to 4.2.0.195 (excl.)
  • affected from 4.3.0 to 4.3.0.106 (excl.)
  • affected from 4.4.0 to 4.4.0.70 (excl.)
  • affected from 4.5.0 to 4.5.0.55 (excl.)
  • affected from 4.6.0 to 4.6.0.19 (excl.)
Vendor WSO2
Product WSO2 Traffic Manager
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.54 (excl.)
  • affected from 4.6.0 to 4.6.0.19 (excl.)
Vendor WSO2
Product WSO2 API Control Plane
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.56 (excl.)
  • affected from 4.6.0 to 4.6.0.20 (excl.)
Vendor WSO2
Product WSO2 Universal Gateway
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.55 (excl.)
  • affected from 4.6.0 to 4.6.0.19 (excl.)
Vendor WSO2
Product WSO2 Open Banking AM
Versions Default: unaffected
  • unknown from 0 to 2.0.0 (excl.)
  • affected from 2.0.0 to 2.0.0.369 (excl.)
Vendor WSO2
Product WSO2 Identity Server
Versions Default: unaffected
  • unknown from 0 to 5.10.0 (excl.)
  • affected from 5.10.0 to 5.10.0.345 (excl.)
  • affected from 5.11.0 to 5.11.0.395 (excl.)
  • affected from 6.0.0 to 6.0.0.229 (excl.)
  • affected from 6.1.0 to 6.1.0.208 (excl.)
Vendor WSO2
Product WSO2 Open Banking IAM
Versions Default: unaffected
  • unknown from 0 to 2.0.0 (excl.)
  • affected from 2.0.0 to 2.0.0.389 (excl.)
Vendor WSO2
Product WSO2 Identity Server as Key Manager
Versions Default: unaffected
  • unknown from 0 to 5.10.0 (excl.)
  • affected from 5.10.0 to 5.10.0.338 (excl.)
Vendor WSO2
Product WSO2 Carbon OAuth
Versions Default: unknown
  • affected from 6.4.2 to 6.4.2.154 (excl.)
  • affected from 6.4.111 to 6.4.111.131 (excl.)
  • affected from 6.4.176 to 6.4.176.35 (excl.)
  • affected from 6.4.180 to 6.4.180.17 (excl.)
  • affected from 6.8.0 to 6.8.0.46 (excl.)
  • affected from 6.9.6 to 6.9.6.34 (excl.)
  • affected from 6.11.21 to 6.11.21.59 (excl.)
  • affected from 6.13.16 to 6.13.16.27 (excl.)
  • affected from 6.13.19 to 6.13.19.19 (excl.)
  • affected from 6.13.27 to 6.13.27.15 (excl.)
  • affected from 6.13.41 to 6.13.41.4 (excl.)
  • unaffected from 6.11.53 to * (incl.)

Solutions

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-2753/#solution

References

Problem Types

  • CWE-613: Insufficient Session Expiration CWE

Impacts

  • CAPEC-562 CAPEC-562: Token Abuse