CVE-2024-1248 - CVE House
Back to Database
Status published Medium CVE-2024-1248

Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation

Vulnerability Description

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user. Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1248

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM
Vulnerable Versions:
0, 3.0.0, 3.1.0, 3.2.0, 4.0.0, 4.1.0, 5.8.0, 5.9.0, 5.10.0, 5.11.0, 2.0.0

Timeline

Official Publish: July 4th, 2026
Last Modified: July 6th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.