
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13475 is a cross-tenant consent isolation vulnerability in WSO2 Identity Server and WSO2 API Manager affecting multi-tenanted deployments. The flaw causes the application consent management mechanism to fail to correctly isolate consent scopes between tenants, allowing consent granted in one tenant to be incorrectly applied to SaaS applications with the same name in other tenants. Affected versions include WSO2 Identity Server 5.10.0 through 5.10.0.381, WSO2 API Manager 3.2.0 through 3.2.0.456, and 3.2.1 through 3.2.1.75. The vulnerability was published on July 4, 2026, with a CVSS v3.1 base score of 7.3 (High) per NVD, though the GitHub Advisory Database and ENISA rate it as Low (3.5) based on a more conservative scoring (GitHub Advisory, WSO2 Advisory).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), where the consent management subsystem fails to enforce tenant-boundary checks when resolving consent scopes for SaaS applications. Specifically, when a user grants consent to a SaaS application identified by name within one tenant, the system incorrectly matches and applies that consent to identically named applications in other tenants, bypassing the expected per-tenant authorization flow. Exploitation requires an authenticated user with low privileges to interact with the consent flow (e.g., by granting consent to a SaaS application), and a second tenant must host a SaaS application with the same name. No public proof-of-concept code has been identified (GitHub Advisory, WSO2 Advisory).
Successful exploitation allows SaaS applications in one tenant to access and modify user data belonging to users in other tenants without explicit authorization, resulting in high confidentiality and integrity impact (per NVD scoring). This constitutes a cross-tenant data exposure and privacy violation, potentially enabling unauthorized reads and writes of user information across organizational boundaries. Availability is not impacted, and the vulnerability has no effect on single-tenant deployments (GitHub Advisory, WSO2 Advisory).
IDN_CONSENT_RECEIPT or related consent tables where the tenant domain does not match the application's registered tenant, or where duplicate consent records exist for identically named apps across tenants.WSO2 has released patched versions addressing this vulnerability: WSO2 Identity Server 5.10.0.382 and later, WSO2 API Manager 3.2.0.457 and later, and WSO2 API Manager 3.2.1.76 and later. Organizations should upgrade to these fixed versions as the primary remediation. As a workaround for deployments that cannot immediately upgrade, administrators should implement strict tenant-based isolation in the consent management configuration, audit existing consent grants across tenants to identify any unintended cross-tenant access, and consider adding additional verification steps for SaaS application consent flows. This vulnerability has no impact on single-tenant deployments and requires no action in those environments (WSO2 Advisory, GitHub Advisory).
The vulnerability received limited but broad automated coverage across vulnerability tracking platforms including VulnDB, CIRCL, INCIBE-CERT, and ENISA's EUVD shortly after publication. A Reddit post in r/pwnhub discussed the cross-tenant consent sharing issue, and the CVE was noted on social platforms including Bluesky and Nitter. No significant researcher commentary or vendor statements beyond the official WSO2 advisory have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."