CVE-2025-10908
📛 CVE Title
Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized Access
Description
Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security control that should prevent access to accounts that have been locked. This vulnerability may allow unauthorized access to applications and sensitive data associated with accounts that should have been restricted via the account lock mechanism. It also undermines the effectiveness of the account lock mechanism intended to prevent further login attempts.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- WSO2
- CVSS severity
- high
- CVSS score
- 7.3 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Effective score
- 7.3 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-863 - Reserved
- 2025-09-24
- Published
- 2026-05-11 11:01 UTC
- Last updated
- 2026-05-11 20:38 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/10xxx/CVE-2025-10908.json
- Linked Threat
- CVE-2025-10908 — CVE-2025-10908
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-209756 - Assigner
- WSO2
- Published
- May 11, 2026, 9:01:43 AM
- Updated
- May 11, 2026, 6:38:02 PM
- EUVD base score (CVSS 3.1)
-
7.3 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - EUVD-reported EPSS
- 0.0700
- Vendors
- WSO2
- Products
-
WSO2 Carbon MagicLink Authenticator Module (1.1.31 <1.1.31.2)WSO2 Identity Server (7.0.0 <7.0.0.124)WSO2 Carbon MagicLink Authenticator Module (1.1.22 <1.1.22.5)WSO2 Carbon MagicLink Authenticator Module (1.1.5 <1.1.5.2)WSO2 Carbon MagicLink Authenticator Module (1.1.0 <1.1.0.1)WSO2 Identity Server (6.1.0 <6.1.0.248)WSO2 Carbon MagicLink Authenticator ModuleWSO2 Identity ServerWSO2 Identity Server (6.0.0 <6.0.0.249)WSO2 Identity Server (7.1.0 <7.1.0.31)
ENISA description: Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security control that should prevent access to accounts that have been locked. This vulnerability may allow unauthorized access to applications and sensitive data associated with accounts that should have been restricted via the account lock mechanism. It also undermines the effectiveness of the account lock mechanism intended to prevent further login attempts.
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| WSO2 | WSO2 Identity Server |
0 (unknown),
6.0.0 (affected),
6.1.0 (affected),
7.0.0 (affected),
7.1.0 (affected)
|
— |
| WSO2 | WSO2 Carbon MagicLink Authenticator Module |
1.1.0 (affected),
1.1.5 (affected),
1.1.22 (affected),
1.1.31 (affected),
1.1.43 (unaffected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (3)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2025-10908 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2025-10908 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
Remediations (20)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cybersecuritynews.com
Microsoft rolled out its October 2025 Patch Tuesday updates, addressing a staggering 172 vulnerabilities across its ecosystem, including four zero-day flaws, of which two are actively exploited in the wild.
2026-05-23 21:02 UTC -
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
2026-05-23 21:02 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-23 21:02 UTC -
web:securitricks.com
CVE CVE-2025-10908 - Score : 7.3 - Source : ed10eef1-636d-4fbe-9993-6890dfa878f8 - Description : Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security control that should prevent access to accounts that have been locked. This vulnerability may allow ...
2026-05-23 21:02 UTC -
web:securityvulnerability.io
What is CVE-2025-10908 ? A vulnerability in WSO2 Identity Server allows unauthorized access to locked user accounts through Magic Link or Pass Key methods. When user account state validation is improperly handled during authentication, it enables malicious actors to bypass the security controls designed to prevent access to restricted accounts. This flaw compromises the integrity of the account ...
2026-05-23 21:02 UTC -
web:support.microsoft.com
Summary Improvements and fixes included in this update How to obtain and install the update More information File information Information about protection and security Summary This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories: CVE -2026-40370 - SQL Server Remote Code Execution Vulnerability The ...
2026-05-23 21:02 UTC -
web:www.absolute.com
Microsoft Patch Tuesday August 2025 delivers 109 fixes, including critical vulnerabilities in MSMQ, NTLM, and graphics components. Stay protected.
2026-05-23 21:02 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's October 2025 Patch Tuesday, which includes security updates for 172 flaws, including six zero-day vulnerabilities. Get patching!
2026-05-23 21:02 UTC -
web:www.crowdstrike.com
Microsoft has released security updates for 172 vulnerabilities, including 2 publicly disclosed, 3 zero-days, and 8 critical, in its October 2025 Patch Tuesday rollout.
2026-05-23 21:02 UTC -
web:www.techrepublic.com
Microsoft's October 2025 Patch Tuesday underscores the company's continued focus on addressing critical and actively exploited vulnerabilities, even as it sunsets support for Windows 10.
2026-05-23 21:02 UTC -
web:app.opencve.io
Explore the latest vulnerabilities and security issues in the CVE database
2026-05-26 02:50 UTC -
web:cybernews.com
Ubiquiti has released emergency updates for its UniFi Network Application - a critical vulnerability allows hackers to compromise systems without credentials.
2026-05-26 02:50 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-05-26 02:50 UTC -
web:forums.ea.com
Broken and Updated Sims 4 Mods and CC: patch 1.124, May 12 and 21, 2026 About This Thread This thread tracks Sims 4 mods and CC that have been "broken" or made obsolete by game update 1.124, May 12, 2026, and the May 21 hotfix, or declared unsupported by their creators.
2026-05-26 02:50 UTC -
web:msrc.microsoft.com
Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates.
2026-05-26 02:50 UTC -
web:patch.moe
Age Verification Are you 18 years or older? YES NO
2026-05-26 02:50 UTC -
web:playvalorant.com
Partnership with Discord, revamped Settings page, and more.
2026-05-26 02:50 UTC -
web:www.csoonline.com
Days after Microsoft patched a high-severity issue affecting its Windows Defender antivirus tool through April's Patch Tuesday, researchers warn of another vulnerability that could enable SYSTEM ...
2026-05-26 02:50 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-26 02:50 UTC -
web:www.screwfix.com
Screwfix offers a wide range of trade tools and hardware at competitive prices with convenient delivery and collection options.
2026-05-26 02:50 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-10908.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-10908",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-05-11T18:37:41.307369Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T18:38:02.953Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WSO2 Identity Server",
"vendor": "WSO2",
"versions": [
{
"lessThan": "6.0.0",
"status": "unknown",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "6.0.0.249",
"status": "affected",
"version": "6.0.0",
"versionType": "custom"
},
{
"lessThan": "6.1.0.248",
"status": "affected",
"version": "6.1.0",
"versionType": "custom"
},
{
"lessThan": "7.0.0.124",
"status": "affected",
"version": "7.0.0",
"versionType": "custom"
},
{
"lessThan": "7.1.0.31",
"status": "affected",
"version": "7.1.0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"packageName": "org.wso2.carbon.identity.local.auth.magiclink:org.wso2.carbon.identity.application.authenticator.magiclink",
"product": "WSO2 Carbon MagicLink Authenticator Module",
"vendor": "WSO2",
"versions": [
{
"lessThan": "1.1.0.1",
"status": "affected",
"version": "1.1.0",
"versionType": "custom"
},
{
"lessThan": "1.1.5.2",
"status": "affected",
"version": "1.1.5",
"versionType": "custom"
},
{
"lessThan": "1.1.22.5",
"status": "affected",
"version": "1.1.22",
"versionType": "custom"
},
{
"lessThan": "1.1.31.2",
"status": "affected",
"version": "1.1.31",
"versionType": "custom"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "1.1.43",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0.0.249",
"versionStartIncluding": "6.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.0.248",
"versionStartIncluding": "6.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.0.124",
"versionStartIncluding": "7.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.0.31",
"versionStartIncluding": "7.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:wso2_carbon_magiclink_authenticator_module:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.1.0.1",
"versionStartIncluding": "1.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:wso2_carbon_magiclink_authenticator_module:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.1.5.2",
"versionStartIncluding": "1.1.5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:wso2_carbon_magiclink_authenticator_module:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.1.22.5",
"versionStartIncluding": "1.1.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:wso2_carbon_magiclink_authenticator_module:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.1.31.2",
"versionStartIncluding": "1.1.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:wso2_carbon_magiclink_authenticator_module:*:*:*:*:*:*:*:*",
"versionEndIncluding": "*",
"versionStartIncluding": "1.1.43",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security control that should prevent access to accounts that have been locked.\n\nThis vulnerability may allow unauthorized access to applications and sensitive data associated with accounts that should have been restricted via the account lock mechanism. It also undermines the effectiveness of the account lock mechanism intended to prevent further login attempts."
}
],
"value": "Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security control that should prevent access to accounts that have been locked.\n\nThis vulnerability may allow unauthorized access to applications and sensitive data associated with accounts that should have been restricted via the account lock mechanism. It also undermines the effectiveness of the account lock mechanism intended to prevent further login attempts."
}
],
"impacts": [
{
"capecId": "CAPEC-538",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-538 CAPEC-538: Bypass Authentication"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T09:01:43.938Z",
"orgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"shortName": "WSO2"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4388/"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<span style=\"background-color: transparent;\">Follow the instructions given on </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4388/#solution\"><span style=\"background-color: transparent;\">https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4388/#solution</span></a> <br>"
}
],
"value": "Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4388/#solution"
}
],
"source": {
"advisory": "WSO2-2025-4388",
"discovery": "INTERNAL"
},
"title": "Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized Access",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "ed10eef1-636d-4fbe-9993-6890dfa878f8",
"assignerShortName": "WSO2",
"cveId": "CVE-2025-10908",
"datePublished": "2026-05-11T09:01:43.938Z",
"dateReserved": "2025-09-24T09:32:17.201Z",
"dateUpdated": "2026-05-11T18:38:02.953Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}