CVE-2025-12317 MEDIUM

CVE-2025-12317: Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows Retained Access Privileges

Vendor Wso2
Product WSO2 Enterprise Integrator
Weakness CWE-613 · Insufficient session expiration
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.

Key dates

02Disclosure timeline

August 6, 2026 CVE published