CVE-2025-13909
Last modified
CVE-2025-13909 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Identity Server | >= 7.0.0, < 7.0.0.134 |
| Wso2 | Identity Server | >= 7.1.0, < 7.1.0.42 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-13909?
How severe is CVE-2025-13909?
How do I fix CVE-2025-13909?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13903The PullQuote plugin for WordPress is vulnerable to Stored C…6.4
- CVE-2025-13904The WPGancio plugin for WordPress is vulnerable to Stored Cr…6.4
- CVE-2025-13905CWE-276: Incorrect Default Permissions vulnerability exists …7
- CVE-2025-13906The WP Flot plugin for WordPress is vulnerable to Stored Cro…6.4
- CVE-2025-13907The CSS3 Buttons plugin for WordPress is vulnerable to Store…6.4
- CVE-2025-13908The The Tooltip plugin for WordPress is vulnerable to Stored…6.4
- CVE-2025-1391A flaw was found in the Keycloak organization feature, which…5.4
- CVE-2025-13910The WP-WebAuthn plugin for WordPress is vulnerable to Unauth…6.1
- CVE-2025-13911The vulnerability affects Ignition SCADA applications where …7.3
- CVE-2025-13912Multiple constant-time implementations in wolfSSL before ver…1
- CVE-2025-13913A privileged Ignition user, intentionally or otherwise, impo…6.8
- CVE-2025-13914A Key Exchange without Entity Authentication vulnerability i…8.1
Are you affected by CVE-2025-13909?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
