What is CVE-2025-12627?
This vulnerability involves improper management of refresh tokens during user impersonation in WSO2 Identity Server. An attacker who has obtained an access token for an impersonated session can exploit the refresh token grant to acquire new access tokens, extending their unauthorized access. Applying the vendor-supplied update is recommended.
Azərbaycanca: Bu zəiflik WSO2 Identity Server-də istifadəçi təqlidi (impersonation) zamanı refresh token-lərin düzgün idarə olunmaması ilə bağlıdır. Təcavüzkar ələ keçirdiyi təqlid edilmiş sessiyaya aid access token vasitəsilə refresh token grant-dən istifadə edərək yeni access token-lər əldə edə və öz imtiyazlarını uzada bilər. WSO2 tərəfindən buraxılmış yeniləməni tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: WSO2
FAQ1
Through which mechanism can CVE-2025-12627 in WSO2 Identity Server lead to privilege extension?
An attacker can use the refresh token grant with an obtained impersonated session's access token to acquire new access tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.