CVE-2024-8995: Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access

Published Aug 6, 2026
·
Updated

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused.

If an attacker possesses both the authorization code and the associated client credentials (client ID and client secret), they can leverage these unused codes to obtain access tokens on behalf of users who have already been deleted. This may lead to unauthorized access to sensitive resources and services, contingent on the scopes originally authorized for the compromised authorization code.

Affected Software

1 affected component
WSO2 WSO2

Event History

Aug 6, 2026
CVE Published
via MITRE·07:32 AM
Data Sourced
via MITRE·07:32 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-8995?

CVE-2024-8995 has a medium severity score of 4.9.

2

How do I fix CVE-2024-8995?

To fix CVE-2024-8995, ensure that authorization codes issued to users are invalidated when the user account is deleted.

3

What systems are affected by CVE-2024-8995?

CVE-2024-8995 affects multiple WSO2 products that utilize authorization codes.

4

What type of attack does CVE-2024-8995 enable?

CVE-2024-8995 allows for unauthorized access due to the reuse of authorization codes from deleted users.

5

Is user intervention required to mitigate CVE-2024-8995?

Yes, user intervention is required to implement proper invalidation of authorization codes for deleted accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203