CVE-2025-12624 - CVE House
Back to Database
Status published Medium CVE-2025-12624

Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock

Vulnerability Description

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts. The security consequence is that a locked user account can maintain access to protected resources through the use of existing, unexpired access tokens. This creates a security gap where access control policies are bypassed, potentially leading to unauthorized data access or actions until the tokens naturally expire.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12624

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

WSO2 Identity Server
Vulnerable Versions:
0, 5.2.0

Timeline

Official Publish: April 16th, 2026
Last Modified: April 16th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

Weaknesses (CWE)