CVE-2025-13909
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information.
Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.35%
- Percentil entre todas las CVEs puntuadas: 26
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20, CWE-200
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-13909",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-13909",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-08-06T12:33:10.840905Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"affectedData": [
{
"vendor": "WSO2",
"product": "WSO2 Identity Server",
"versions": [
{
"status": "affected",
"version": "7.0.0",
"lessThan": "7.0.0.134",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.1.0",
"lessThan": "7.1.0.42",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WSO2",
"product": "WSO2 Carbon Identity Application Authentication Framework",
"versions": [
{
"status": "affected",
"version": "7.0.78",
"lessThan": "7.0.78.162",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.8.23",
"lessThan": "7.8.23.66",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "7.8.550",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"packageName": "org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework",
"defaultStatus": "unknown"
},
{
"vendor": "WSO2",
"product": "WSO2 Carbon MagicLink Authenticator Module",
"versions": [
{
"status": "affected",
"version": "1.1.22",
"lessThan": "1.1.22.6",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.1.31",
"lessThan": "1.1.31.3",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.1.45",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"packageName": "org.wso2.carbon.identity.local.auth.magiclink:org.wso2.carbon.identity.application.authenticator.magiclink",
"defaultStatus": "unknown"
},
{
"vendor": "WSO2",
"product": "WSO2 Carbon Abstract OTP Authenticator",
"versions": [
{
"status": "affected",
"version": "1.0.5",
"lessThan": "1.0.5.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.0.10",
"lessThan": "1.0.10.1",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.0.24",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"packageName": "org.wso2.carbon.identity.auth.otp.commons:org.wso2.carbon.identity.auth.otp.core",
"defaultStatus": "unknown"
},
{
"vendor": "WSO2",
"product": "Email OTP Authenticator",
"versions": [
{
"status": "affected",
"version": "1.0.30",
"lessThan": "1.0.30.4",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "1.0.51",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"packageName": "org.wso2.carbon.identity.local.auth.emailotp:org.wso2.carbon.identity.local.auth.emailotp",
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-08-06T08:16:28.803",
"references": [
{
"url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4731/",
"tags": [
"Vendor Advisory"
],
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information.\n\nSuccessful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers."
},
{
"lang": "es",
"value": "El sistema acepta solicitudes de autenticación sin validación suficiente para hacer cumplir el aislamiento de inquilinos al usar OTP por correo electrónico, OTP por SMS o Magic Link como autenticadores de primer factor. Esta falla al separar adecuadamente los datos de usuario entre inquilinos puede llevar a la exposición de información de identificación personal.\n\nLa explotación exitosa permite a un atacante divulgar información de identificación personal de usuarios en diferentes inquilinos, lo que resulta en violaciones de privacidad y posible incumplimiento normativo. Esto puede incluir acceso no autorizado a detalles de usuario como números de móvil."
}
],
"lastModified": "2026-09-29T14:10:00.117",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB23A14D-279C-4E26-822D-339A5F9943BC",
"versionEndExcluding": "7.0.0.134",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "106CFF22-4275-40BD-82FA-56BE38EB1280",
"versionEndExcluding": "7.1.0.42",
"versionStartIncluding": "7.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ed10eef1-636d-4fbe-9993-6890dfa878f8"
}