CVE Feed

    Dashboard / CVE / CVE-2025-12624

    CVE-2025-12624

    Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts. The security consequence is that a locked user account can maintain access to protected resources through the use of existing, unexpired access tokens. This creates a security gap where access control policies are bypassed, potentially leading to unauthorized data access or actions until the tokens naturally expire.

    Published:Apr 16, 2026
    Last Modified:Apr 23, 2026
    EPS:Apr 16, 2026
    EPSS Score:0.00012
    CVSS Score:6

    Affected Products

    Vendor
    Wso2
    Product
    Identity Server
    Vendor
    Wso2
    Product
    Wso2 Identity Server

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High