
CVE-2025-12624 Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously is… https://www.cve.org/CVERecord?id=CVE-2025-12624
Post summary
The post announces that CVE-2025-12624 involves failure to revoke active tokens when a WSO2 Identity Server account is locked, but it provides no PoC, exploit, patch, or evidence of active exploitation.
