CVE-2025-13475 Details
Description
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing. This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization. This can lead to unauthorized data access and privacy violations. This vulnerability has no impact if the deployment does not support multi-tenancy.
A vulnerability exists in WSO2 API Manager versions 3.2.1 and 3.2.0, as well as WSO2 Identity Server version 5.10.0, due to improper management of application consent in multi-tenant deployments. This flaw allows consent granted by a user for a specific SaaS application in one tenant to be incorrectly applied to SaaS applications with the same name in other tenants. As a result, there can be unintended cross-tenant sharing of consent, leading to unauthorized access and modification of user data by SaaS applications in different tenants without explicit user authorization. This vulnerability may cause privacy violations and non-compliance with data protection regulations.
Users of WSO2 API Manager should update to version 3.2.1 or 3.2.0, while WSO2 Identity Server users should update to version 5.10.0. After applying the update, create the IDN_OAUTH2_USER_CONSENT and IDN_OAUTH2_USER_CONSENTED_SCOPES tables in the identity database using the available table creation scripts.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-1613/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 api manager | >= 3.2.0, < 3.2.0.457 >= 3.2.1, < 3.2.1.76 |
CPE
Remediation
| |
| wso2 identity server | >= 5.10.0, < 5.10.0.382 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 4, 2026 | New CVE Received | WSO2 LLC |