CVE-2025-13909 | WSO2 Identity Server improper authorization

SecurityVulns

A vulnerability was found in WSO2 Identity Server. It has been classified as problematic. Affected is an unknown function of the component Carbon Identity Application Authentication Framework/Carbon MagicLink Authenticator Module/Carbon Abstract OTP Authenticator/Email OTP Authenticator. Performing a manipulation results in improper authorization.

This vulnerability is reported as CVE-2025-13909. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More