CVE-2025-0663 Details
Description
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user in one tenant to forge authentication cookies for users in other tenants. Because the Auto-Login feature is enabled by default, this flaw may allow an attacker to gain unauthorized access and potentially take over accounts in other tenants. Successful exploitation requires access to Adaptive Authentication functionality, which is typically restricted to high-privileged users. The vulnerability is only exploitable when Auto-Login is enabled, reducing its practical impact in deployments where the feature is disabled.
A cross-tenant authentication vulnerability has been identified in multiple WSO2 products, including WSO2 Identity Server, WSO2 Identity Server as Key Manager, and WSO2 Open Banking IAM. This vulnerability arises from improper cryptographic design in Adaptive Authentication, where a single cryptographic key is used across all tenants to sign authentication cookies. This flaw enables a privileged user in one tenant to forge authentication cookies for users in other tenants. The issue is exacerbated by the fact that the Auto-Login feature is enabled by default, potentially allowing an attacker to gain unauthorized access and take over accounts in other tenants. Exploitation requires access to the Adaptive Authentication functionality, which is typically restricted to high-privileged users, and is only possible when Auto-Login is enabled.
WSO2 community users are advised to migrate to the latest version of the respective WSO2 products. Support subscription holders should update their product to the specified update level or a higher update level to apply the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-3864/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| wso2 identity server | 5.10.0 5.11.0 6.0.0 6.1.0 7.0.0 |
CPE
Remediation
| |
| wso2 identity server as key manager | 5.10.0 |
CPE
Remediation
| |
| wso2 open banking iam | 2.0.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2025 | Initial Analysis | [email protected] |
| Sep 25, 2025 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | New CVE Received | WSO2 LLC |