CVE-2025-13909 PUBLISHED

Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure

Assigner: WSO2
Reserved: 02.12.2025 Published: 06.08.2026 Updated: 06.08.2026

The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information.

Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor WSO2
Product WSO2 Identity Server
Versions Default: unaffected
  • affected from 7.0.0 to 7.0.0.134 (excl.)
  • affected from 7.1.0 to 7.1.0.42 (excl.)
Vendor WSO2
Product WSO2 Carbon Identity Application Authentication Framework
Versions Default: unknown
  • affected from 7.0.78 to 7.0.78.162 (excl.)
  • affected from 7.8.23 to 7.8.23.66 (excl.)
  • unaffected from 7.8.550 to * (incl.)
Vendor WSO2
Product WSO2 Carbon MagicLink Authenticator Module
Versions Default: unknown
  • affected from 1.1.22 to 1.1.22.6 (excl.)
  • affected from 1.1.31 to 1.1.31.3 (excl.)
  • unaffected from 1.1.45 to * (incl.)
Vendor WSO2
Product WSO2 Carbon Abstract OTP Authenticator
Versions Default: unknown
  • affected from 1.0.5 to 1.0.5.4 (excl.)
  • affected from 1.0.10 to 1.0.10.1 (excl.)
  • unaffected from 1.0.24 to * (incl.)
Vendor WSO2
Product Email OTP Authenticator
Versions Default: unknown
  • affected from 1.0.30 to 1.0.30.4 (excl.)
  • unaffected from 1.0.51 to * (incl.)

Solutions

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4731/#solution

References

Problem Types

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE
  • CWE-20: Improper Input Validation CWE

Impacts

  • CAPEC-28 CAPEC-28: Data Leakage
  • CAPEC-14 CAPEC-14: Cross-Tenant Access