CVE-2025-12627 | WSO2 Identity Server/Carbon OAuth User Impersonation Flow improper authorization
A vulnerability described as critical has been identified in WSO2 Identity Server and Carbon OAuth. The affected element is an unknown function of the component User Impersonation Flow. Executing a manipulation can lead to improper authorization.
The identification of this vulnerability is CVE-2025-12627. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More