Wso2 carbon identity application authentication framework
This hub aggregates every CVE we track for Wso2 carbon identity application authentication framework, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
1
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM2HIGH1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
1
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting Wso2 carbon identity application authentication framework.
- CVE-2025-5802Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery5.3
- CVE-2025-15039Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products9.4
- CVE-2025-13909Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure4.3
- CVE-2023-6837Incorrect Authorization in Multiple WSO2 Products via Federated Authentication with JIT Provisioning Leading to User Impersonation8.5
Product normalization is registry-driven with AI assist and human review. How it works