CVE-2025-13475
WSO2 API Manager vulnerability analysis and mitigation

Overview

CVE-2025-13475 is a cross-tenant consent isolation vulnerability in WSO2 Identity Server and WSO2 API Manager affecting multi-tenanted deployments. The flaw causes the application consent management mechanism to fail to correctly isolate consent scopes between tenants, allowing consent granted in one tenant to be incorrectly applied to SaaS applications with the same name in other tenants. Affected versions include WSO2 Identity Server 5.10.0 through 5.10.0.381, WSO2 API Manager 3.2.0 through 3.2.0.456, and 3.2.1 through 3.2.1.75. The vulnerability was published on July 4, 2026, with a CVSS v3.1 base score of 7.3 (High) per NVD, though the GitHub Advisory Database and ENISA rate it as Low (3.5) based on a more conservative scoring (GitHub Advisory, WSO2 Advisory).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), where the consent management subsystem fails to enforce tenant-boundary checks when resolving consent scopes for SaaS applications. Specifically, when a user grants consent to a SaaS application identified by name within one tenant, the system incorrectly matches and applies that consent to identically named applications in other tenants, bypassing the expected per-tenant authorization flow. Exploitation requires an authenticated user with low privileges to interact with the consent flow (e.g., by granting consent to a SaaS application), and a second tenant must host a SaaS application with the same name. No public proof-of-concept code has been identified (GitHub Advisory, WSO2 Advisory).

Impact

Successful exploitation allows SaaS applications in one tenant to access and modify user data belonging to users in other tenants without explicit authorization, resulting in high confidentiality and integrity impact (per NVD scoring). This constitutes a cross-tenant data exposure and privacy violation, potentially enabling unauthorized reads and writes of user information across organizational boundaries. Availability is not impacted, and the vulnerability has no effect on single-tenant deployments (GitHub Advisory, WSO2 Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target multi-tenanted WSO2 Identity Server or API Manager deployment running a vulnerable version (IS < 5.10.0.382, APIM < 3.2.0.457 or < 3.2.1.76).
  2. Register a malicious SaaS application: In a tenant controlled by the attacker, register a SaaS application using the same name as a legitimate SaaS application registered in a victim tenant.
  3. Trigger victim user consent: Induce a victim user (in any tenant) to grant consent to the attacker-controlled application, or wait for a user to grant consent to the legitimate application in their tenant.
  4. Exploit consent leakage: Due to the missing tenant-boundary check, the consent granted in one tenant is incorrectly resolved and applied to the identically named application in the attacker's tenant.
  5. Access victim data: Use the improperly shared consent token/scope to access or modify the victim user's data through the attacker-controlled SaaS application, bypassing explicit authorization (GitHub Advisory, WSO2 Advisory).

Indicators of compromise

  • Logs: Consent grant audit logs showing the same consent scope being applied to SaaS applications across multiple tenants; unexpected consent records in the WSO2 Identity Server consent management database for applications in tenants where the user has not explicitly interacted.
  • Application Behavior: SaaS applications in one tenant successfully accessing user data from another tenant without a corresponding explicit consent grant event for that tenant.
  • Database: Consent entries in the IDN_CONSENT_RECEIPT or related consent tables where the tenant domain does not match the application's registered tenant, or where duplicate consent records exist for identically named apps across tenants.

Mitigation and workarounds

WSO2 has released patched versions addressing this vulnerability: WSO2 Identity Server 5.10.0.382 and later, WSO2 API Manager 3.2.0.457 and later, and WSO2 API Manager 3.2.1.76 and later. Organizations should upgrade to these fixed versions as the primary remediation. As a workaround for deployments that cannot immediately upgrade, administrators should implement strict tenant-based isolation in the consent management configuration, audit existing consent grants across tenants to identify any unintended cross-tenant access, and consider adding additional verification steps for SaaS application consent flows. This vulnerability has no impact on single-tenant deployments and requires no action in those environments (WSO2 Advisory, GitHub Advisory).

Community reactions

The vulnerability received limited but broad automated coverage across vulnerability tracking platforms including VulnDB, CIRCL, INCIBE-CERT, and ENISA's EUVD shortly after publication. A Reddit post in r/pwnhub discussed the cross-tenant consent sharing issue, and the CVE was noted on social platforms including Bluesky and Nitter. No significant researcher commentary or vendor statements beyond the official WSO2 advisory have been identified (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related WSO2 API Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-2053CRITICAL10
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesJun 26, 2026
CVE-2026-4249HIGH8.6
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesJul 06, 2026
CVE-2025-13475HIGH7.3
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesJul 04, 2026
CVE-2025-8591MEDIUM6.1
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:identity_server
NoYesJul 06, 2026
CVE-2024-1248MEDIUM5.3
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesJul 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management