
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-1248 is an authorization bypass vulnerability in WSO2's silent Just-In-Time (JIT) provisioning feature for federated authentication, which fails to properly segregate user roles when a federated user shares a username with an existing local user. This allows the JIT provisioning process to overwrite the roles of local users with those assigned to the federated user. The vulnerability was disclosed on July 4, 2026, and affects multiple WSO2 products including Identity Server (5.8.0–5.11.x), API Manager (3.0.0–4.1.x), Identity Server as Key Manager (5.9.0–5.10.x), Open Banking AM (2.0.0), and Open Banking IAM (2.0.0). NVD assigns a CVSS v3.1 base score of 5.3 (Medium), while WSO2 as the CNA rates it 4.8 (Medium) (GitHub Advisory, WSO2 Advisory).
The root cause is improper role segregation in the silent JIT provisioning workflow (classified as CWE-298 by WSO2, though this CWE label — Improper Validation of Certificate Expiration — appears to be a misclassification; the actual issue is closer to an authorization/identity confusion flaw). When a federated identity provider (IDP) with silent JIT provisioning enabled authenticates a user whose username matches an existing local account, the provisioning logic overwrites the local user's roles with those from the federated IDP rather than treating the accounts as distinct. Exploitation requires two preconditions: (1) a federated IDP configured with silent JIT provisioning enabled, and (2) the attacker's knowledge of a valid local username. The attack is network-accessible and requires no authentication or user interaction, but the high attack complexity (per WSO2's scoring) reflects the need to control or abuse a federated IDP (GitHub Advisory, WSO2 Advisory).
Successful exploitation allows an attacker to overwrite the roles of existing local users with roles defined in the federated IDP, which typically carry minimal access rights unless the federated IDP administrator has explicitly granted elevated permissions. The primary impact is an integrity violation — legitimate user permissions are silently degraded or altered — which could disrupt access control policies and cause denial of service for affected accounts. Confidentiality is not directly impacted, and data exfiltration is not a direct consequence, though role manipulation could be leveraged as a stepping stone to further abuse in environments where federated IDP roles carry significant privileges (GitHub Advisory, WSO2 Advisory).
WSO2 has released patched versions addressing this vulnerability. Organizations should upgrade to the following minimum versions: WSO2 Identity Server 5.8.0.101, 5.9.0.138, 5.10.0.284, or 5.11.0.321; WSO2 API Manager 3.0.0.153, 3.1.0.267, 3.2.0.351, 4.0.0.269, or 4.1.0.169; WSO2 Identity Server as Key Manager 5.9.0.148 or 5.10.0.280; WSO2 Open Banking AM 2.0.0.313; WSO2 Open Banking IAM 2.0.0.333. As a workaround where patching is not immediately possible, administrators should disable silent JIT provisioning, enforce strict username uniqueness validation between federated and local user stores, and audit federated IDP configurations to ensure roles granted do not exceed intended access levels (WSO2 Advisory).
The vulnerability received limited but standard community coverage upon disclosure in early July 2026, with automated aggregation on platforms such as Reddit's r/pwnhub and CVE tracking services. No notable independent researcher commentary or significant media coverage has been identified beyond routine vulnerability database entries and social media CVE notification accounts (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."