Answer in brief
CVE-2025-13909 records a Unknown severity vulnerability in Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure. The current sources do not mark it as known exploited. The current feed maps WSO2/Email OTP Authenticator (generic), WSO2/WSO2 Carbon Abstract OTP Authenticator (generic), WSO2/WSO2 Carbon Identity Application Authentication Framework (generic), WSO2/WSO2 Carbon MagicLink Authenticator Module (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/Email OTP Authenticator (generic), WSO2/WSO2 Carbon Abstract OTP Authenticator (generic), WSO2/WSO2 Carbon Identity Application Authentication Framework (generic), WSO2/WSO2 Carbon MagicLink Authenticator Module (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/Email OTP Authenticatorgeneric | >=1.0.30 <1.0.30.4 | 1.0.30.4 |
| WSO2/WSO2 Carbon Abstract OTP Authenticatorgeneric | >=1.0.5 <1.0.5.4 || >=1.0.10 <1.0.10.1 | 1.0.5.4, 1.0.10.1 |
| WSO2/WSO2 Carbon Identity Application Authentication Frameworkgeneric | >=7.0.78 <7.0.78.162 || >=7.8.23 <7.8.23.66 | 7.0.78.162, 7.8.23.66 |
| WSO2/WSO2 Carbon MagicLink Authenticator Modulegeneric | >=1.1.22 <1.1.22.6 || >=1.1.31 <1.1.31.3 | 1.1.22.6, 1.1.31.3 |
| WSO2/WSO2 Identity Servergeneric | >=7.0.0 <7.0.0.134 || >=7.1.0 <7.1.0.42 | 7.0.0.134, 7.1.0.42 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-13909 records a Unknown severity vulnerability in Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure. The current sources do not mark it as known exploited. The current feed maps WSO2/Email OTP Authenticator (generic), WSO2/WSO2 Carbon Abstract OTP Authenticator (generic), WSO2/WSO2 Carbon Identity Application Authentication Framework (generic), WSO2/WSO2 Carbon MagicLink Authenticator Module (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/Email OTP Authenticator (generic), WSO2/WSO2 Carbon Abstract OTP Authenticator (generic), WSO2/WSO2 Carbon Identity Application Authentication Framework (generic), WSO2/WSO2 Carbon MagicLink Authenticator Module (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/Email OTP Authenticatorgeneric | >=1.0.30 <1.0.30.4 | 1.0.30.4 |
| WSO2/WSO2 Carbon Abstract OTP Authenticatorgeneric | >=1.0.5 <1.0.5.4 || >=1.0.10 <1.0.10.1 | 1.0.5.4, 1.0.10.1 |
| WSO2/WSO2 Carbon Identity Application Authentication Frameworkgeneric | >=7.0.78 <7.0.78.162 || >=7.8.23 <7.8.23.66 | 7.0.78.162, 7.8.23.66 |
| WSO2/WSO2 Carbon MagicLink Authenticator Modulegeneric | >=1.1.22 <1.1.22.6 || >=1.1.31 <1.1.31.3 | 1.1.22.6, 1.1.31.3 |
| WSO2/WSO2 Identity Servergeneric | >=7.0.0 <7.0.0.134 || >=7.1.0 <7.1.0.42 | 7.0.0.134, 7.1.0.42 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers.
Quoted source text, attributed separately from HOL analysis.