Junglewise Threat Intelligence

CVE-2025-9973: WSO2 Identity Server authorization bypass in adaptive authentication

CVE-2025-9973 · Severity: medium · CVSS 6.4 · Published 2026-05-11

Technologies: Wso2 Identity Server. Vendors: Wso2.

Executive brief

WSO2 Identity Server is a solution used by businesses to manage user identities and access across different departments or client organizations. A security flaw in its multi-organization setup allows an administrator of one organization to interfere with the authentication processes of other organizations on the same server. This could lead to unauthorized access to sensitive data, account takeovers, and the ability to perform critical operations in organizations where the attacker should have no access.

Technical details

A vulnerability in WSO2 Identity Server's adaptive authentication mechanism stems from a failure to validate organization context during flow execution. In multi-tenant or multi-organization deployments, an attacker with high privileges (PR:H) to configure adaptive authentication in one organization can trigger authentication logic against unintended organizations or sub-organizations. This improper access control (CWE-284) allows for the bypass of organizational boundaries, enabling privilege escalation and unauthorized resource access across the deployment. The issue is addressed in WSO2 Identity Server 7.1.0 update level 26 and via a public pull request for the identity-conditional-auth-functions extension.

Affected products

  • WSO2 Identity Server 7.1.0 before update level 26

Timeline

  • 2026-01-26: advisory: Initial vendor advisory published by WSO2
  • 2026-05-11: disclosed: CVE published to NVD
  • 2026-05-27: patched: NVD analysis updated with specific version fixes

References

Related threats