CVE-2025-0663

MEDIUM
Published Sep 23, 2025 Modified Oct 6, 2025 CWE-287

Description

A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user in one tenant to forge authentication cookies for users in other tenants. Because the Auto-Login feature is enabled by default, this flaw may allow an attacker to gain unauthorized access and potentially take over accounts in other tenants. Successful exploitation requires access to Adaptive Authentication functionality, which is typically restricted to high-privileged users. The vulnerability is only exploitable when Auto-Login is enabled, reducing its practical impact in deployments where the feature is disabled.

Is your site exposed to CVE-2025-0663?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.8
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-287 Improper Authentication

Affected Products

Vendor Product
wso2 identity_server
wso2 identity_server
wso2 identity_server
wso2 identity_server
wso2 identity_server
wso2 identity_server_as_key_manager
wso2 open_banking_iam

References

Frequently Asked Questions

What is CVE-2025-0663? +
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user in one tenant to forge authentication cookies for users in other tenants. Because the Auto-Login feature is enabled by default, this flaw may allow an attacker to gain unauthorized access and potentially take over accounts in other tenants. Successful exploitation requires access to Adaptive Authentication functionality, which is typically restricted to high-privileged users. The vulnerability is only exploitable when Auto-Login is enabled, reducing its practical impact in deployments where the feature is disabled. It has a CVSS v3.1 base score of 6.8 (MEDIUM).
How severe is CVE-2025-0663? +
CVE-2025-0663 has a CVSS v3.1 score of 6.8 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-0663? +
CVE-2025-0663 affects products from wso2, specifically: identity_server, identity_server_as_key_manager, open_banking_iam. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-0663? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-0663 — free, no signup required.