SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-12627

This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user.

LOW 2.4EPSS 0.13%

Does this matter?

Lower severity and a low EPSS score (0.13%). Track it; it rarely justifies an emergency change on its own.

Description

The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained an access token for an impersonated user to leverage the refresh token grant to obtain new access tokens, extending their ability to act as the legitimate user. An attacker who gains access to an impersonated user's access token can exploit this weakness to renew their authorization. This results in the continued ability to perform actions on behalf of the actual user, compromising log integrity and traceability by masking the true actor.

CVSS 3.1
2.4 LOWCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
EPSS
0.13% probability · 3th percentile
CISA KEV
Not listed
Weakness
CWE-613
Affected
wso2/identity server
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.