CVE-2024-7487: WSO2 Identity Server
Medium severity, CVSS 5.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.
Affected products
- WSO2 Identity Server: version 7.0.0 only
Published 2025-05-22. Last modified 2026-06-17.