CVE-2024-1248: Role Overwriting via Silent JIT Provisioning in Multiple WSO2 Products Enables Privilege Escalation

Published Jul 4, 2026
·
Updated

The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to the federated user.

Exploitation requires a federated identity provider (IDP) with silent JIT provisioning enabled and an attacker's knowledge of a local user's username. When these conditions are met, a malicious individual can leverage the JIT provisioning process to modify the roles of local users. The overwritten roles are limited to those defined within the federated IDP, typically granting minimal access rights unless explicitly configured otherwise by the federated IDP administrator.

Affected Software

14 affected components
WSO2 Multiple WSO2 Products
WSO2 API Manager>=3.0.0<3.0.0.153
WSO2 API Manager>=3.1.0<3.1.0.267
WSO2 API Manager>=3.2.0<3.2.0.351
WSO2 API Manager>=4.0.0<4.0.0.269
WSO2 API Manager>=4.1.0<4.1.0.169
WSO2 Identity Server>=5.8.0<5.8.0.101
WSO2 Identity Server>=5.9.0<5.9.0.138
WSO2 Identity Server>=5.10.0<5.10.0.284
WSO2 Identity Server>=5.11.0<5.11.0.321
WSO2 Identity Server as Key Manager>=5.9.0<5.9.0.148
WSO2 Identity Server as Key Manager>=5.10.0<5.10.0.280
WSO2 Open Banking AM>=2.0.0<2.0.0.313
WSO2 Open Banking Iam>=2.0.0<2.0.0.333

Event History

Jul 4, 2026
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-1248?

CVE-2024-1248 has a medium severity rating of 4.8.

2

How do I fix CVE-2024-1248?

To fix CVE-2024-1248, ensure proper role segregation during user account creation in your WSO2 product configurations.

3

What type of vulnerability is CVE-2024-1248?

CVE-2024-1248 is a privilege escalation vulnerability caused by role overwriting through silent JIT provisioning.

4

Which products are affected by CVE-2024-1248?

CVE-2024-1248 impacts multiple WSO2 products that implement federated authentication.

5

What can happen if CVE-2024-1248 is exploited?

If exploited, CVE-2024-1248 may allow an attacker to overwrite existing roles of local users, leading to unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203