CVE-2025-13475Disclosure(wso2 / api_manager)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing. This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization. This can lead to unauthorized data access and privacy violations. This vulnerability has no impact if the deployment does not support multi-tenancy.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • api_manager
  • identity_server

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
api_manageridentity_server

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-04: 2Mentions · 2026-07-07: 1Mentions · 2026-07-13: 1Technical Details · 2026-07-04: 2Technical Details · 2026-07-13: 107-0407-0707-13
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-042
Disclosure2
2026-07-071
General1
2026-07-131
General1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-13475 Cross-Tenant Consent Scope Isolation Failure in Multi-Tenanted SaaS Deployments https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13475

    Post summary

    The excerpt lists CVE‑2025‑13475 with a descriptive title and a link, but offers no PoC, exploit, active use, or mitigation details, classifying it as a general disclosure.

    0000075
    4.1K followersView on X
  • VulDB 🛡@vuldb
    General

    It is possible to see elevated activities targeting WSO2 Identity Server and API Manager (CVE-2025-13475) https://vuldb.com/vuln/376337/cti

    Post summary

    The post flags possible elevated activity targeting WSO2 products tied to CVE‑2025‑13475 but provides no concrete exploitation evidence, PoC, patch details, or technical breakdown.

    00000107
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-13475 In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a… https://www.cve.org/CVERecord?id=CVE-2025-13475 ----- Traducción: CVE-2025-13475 En … http://infoflow.cloud`

    Post summary

    The tweet simply announces CVE‑2025‑13475, describing its cross‑tenant consent leakage issue, without any PoC, exploit, or patch information.

    0000023
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13475 In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a… https://www.cve.org/CVERecord?id=CVE-2025-13475

    Post summary

    CVE-2025-13475 is a vulnerability where multi‑tenant deployments fail to isolate consent scopes, potentially allowing a user’s consent granted in one tenant to be incorrectly applied to another tenant.

    00000728
    57.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2api_manager---
Appwso2identity_server---

Explore more