Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4731/#solution
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers. | |
| Title | Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure | |
| First Time appeared |
Wso2
Wso2 email Otp Authenticator Wso2 wso2 Carbon Abstract Otp Authenticator Wso2 wso2 Carbon Identity Application Authentication Framework Wso2 wso2 Carbon Magiclink Authenticator Module Wso2 wso2 Identity Server |
|
| Weaknesses | CWE-20 CWE-200 |
|
| CPEs | cpe:2.3:a:wso2:email_otp_authenticator:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_abstract_otp_authenticator:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_identity_application_authentication_framework:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_magiclink_authenticator_module:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 email Otp Authenticator Wso2 wso2 Carbon Abstract Otp Authenticator Wso2 wso2 Carbon Identity Application Authentication Framework Wso2 wso2 Carbon Magiclink Authenticator Module Wso2 wso2 Identity Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-08-06T12:33:19.505Z
Reserved: 2025-12-02T16:51:30.837Z
Link: CVE-2025-13909
Updated: 2026-08-06T12:33:16.118Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T10:00:05Z