Answer in brief
CVE-2025-14779 records a Low severity (CVSS 3.8) vulnerability in Improper Access Control via Secret Type Management API in WSO2 Identity Server. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 Carbon Identity API Server Secret Management Common (generic), WSO2/WSO2 Carbon Identity API Server Secret Management V1 (generic), WSO2/WSO2 Identity Server (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 3.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 Carbon Identity API Server Secret Management Common (generic), WSO2/WSO2 Carbon Identity API Server Secret Management V1 (generic), WSO2/WSO2 Identity Server (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 Carbon Identity API Server Secret Management Commongeneric | >=1.2.3 <1.2.3.7 || >=1.2.23 <1.2.23.11 || >=1.3.83 <1.3.83.16 | 1.2.3.7, 1.2.23.11, 1.3.83.16 |
| WSO2/WSO2 Carbon Identity API Server Secret Management V1generic | >=1.2.3 <1.2.3.7 || >=1.2.23 <1.2.23.11 || >=1.3.83 <1.3.83.16 | 1.2.3.7, 1.2.23.11, 1.3.83.16 |
| WSO2/WSO2 Identity Servergeneric | >=6.0.0 <6.0.0.261 || >=6.1.0 <6.1.0.262 || >=7.1.0 <7.1.0.46 | 6.0.0.261, 6.1.0.262, 7.1.0.46 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations. Exploitation of this vulnerability can result in the unintended deletion of secrets across the entire deployment, potentially causing configuration failures, service interruptions, and a denial-of-service condition. This vulnerability requires delete permissions for the Secret Type Management REST API, which are by default only granted to administrators.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-14779 records a Low severity (CVSS 3.8) vulnerability in Improper Access Control via Secret Type Management API in WSO2 Identity Server. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 Carbon Identity API Server Secret Management Common (generic), WSO2/WSO2 Carbon Identity API Server Secret Management V1 (generic), WSO2/WSO2 Identity Server (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 3.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 Carbon Identity API Server Secret Management Common (generic), WSO2/WSO2 Carbon Identity API Server Secret Management V1 (generic), WSO2/WSO2 Identity Server (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 Carbon Identity API Server Secret Management Commongeneric | >=1.2.3 <1.2.3.7 || >=1.2.23 <1.2.23.11 || >=1.3.83 <1.3.83.16 | 1.2.3.7, 1.2.23.11, 1.3.83.16 |
| WSO2/WSO2 Carbon Identity API Server Secret Management V1generic | >=1.2.3 <1.2.3.7 || >=1.2.23 <1.2.23.11 || >=1.3.83 <1.3.83.16 | 1.2.3.7, 1.2.23.11, 1.3.83.16 |
| WSO2/WSO2 Identity Servergeneric | >=6.0.0 <6.0.0.261 || >=6.1.0 <6.1.0.262 || >=7.1.0 <7.1.0.46 | 6.0.0.261, 6.1.0.262, 7.1.0.46 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to enforce organizational boundaries, leading to the removal of secrets associated with that type across all organizations. Exploitation of this vulnerability can result in the unintended deletion of secrets across the entire deployment, potentially causing configuration failures, service interruptions, and a denial-of-service condition. This vulnerability requires delete permissions for the Secret Type Management REST API, which are by default only granted to administrators.
Quoted source text, attributed separately from HOL analysis.