Executive brief
WSO2 Identity Server is an enterprise identity and access management platform used to authenticate users and manage permissions across corporate applications. A flaw in its Velocity template processing allows authenticated administrators to inject and execute arbitrary code on the server, potentially leading to full system compromise, data theft, or unauthorized access to all managed identities and applications.
Technical details
The vulnerability is a Server-Side Template Injection (SSTI) in WSO2 Identity Server's use of the Velocity template engine, which processes user-controlled template syntax without adequate sanitization or validation. An authenticated administrator can inject malicious Velocity template directives to execute arbitrary code on the server. The attack requires administrative privileges and is network-accessible to authorized users. Successful exploitation enables remote code execution, data manipulation, and unauthorized information access. Patches are available as specified update levels for affected versions (5.11.0, 6.0.0, 6.1.0).
Affected products
- WSO2 Identity Server 5.11.0, 6.0.0, 6.1.0
Timeline
- 2026-01-23: disclosed
- 2026-02-19: published