CVE-2025-13394: CWE-352: Cross-Site Request Forgery (CSRF) in WSO2 WSO2 Identity Server
CVE-2025-13394 is a Cross-Site Request Forgery (CSRF) vulnerability in the Ajax processor of the Carbon console within WSO2 Identity Server. The vulnerability arises because state-changing operations use the HTTP GET method and rely on the SameSite=Lax cookie attribute for CSRF mitigation, which can be bypassed. This allows attackers to trick authenticated users into unknowingly performing unauthorized actions. Exploitation requires the Carbon console and related services to be publicly accessible, which is against WSO2's security recommendations.
AI Analysis
Technical Summary
The Ajax processor in the Carbon console of WSO2 Identity Server does not adequately protect state-changing operations from CSRF attacks. It uses HTTP GET requests for these operations and relies on the SameSite=Lax cookie attribute, which permits cookies to be sent with cross-origin top-level navigation GET requests. This design flaw allows attackers to cause authenticated users' browsers to execute unintended state-altering requests without their consent. The vulnerability affects multiple specific versions of WSO2 Identity Server. There is no official remediation or patch currently documented, and the vulnerability is only exploitable if the affected services are exposed to the public internet.
Potential Impact
An attacker can perform unauthorized state-changing actions on behalf of authenticated users, potentially leading to data modification, account changes, or loss of user control. The vulnerability does not impact confidentiality but affects integrity and availability due to unauthorized changes and possible service disruption. Exploitation requires user interaction and public exposure of the Carbon console, limiting the attack surface.
Mitigation Recommendations
No official patch or fix is currently documented. WSO2 recommends not exposing the Carbon console and related services to the public internet, which effectively mitigates the risk. Organizations should follow this guidance to prevent exploitation. Monitor vendor advisories for any future updates or patches addressing this vulnerability.
CVE-2025-13394: CWE-352: Cross-Site Request Forgery (CSRF) in WSO2 WSO2 Identity Server
Description
CVE-2025-13394 is a Cross-Site Request Forgery (CSRF) vulnerability in the Ajax processor of the Carbon console within WSO2 Identity Server. The vulnerability arises because state-changing operations use the HTTP GET method and rely on the SameSite=Lax cookie attribute for CSRF mitigation, which can be bypassed. This allows attackers to trick authenticated users into unknowingly performing unauthorized actions. Exploitation requires the Carbon console and related services to be publicly accessible, which is against WSO2's security recommendations.
CVSS v3.1
Score 5.4medium
Affected software
WSO2
WSO2 Identity Server
WSO2
WSO2 API Manager
WSO2
WSO2 Open Banking IAM
WSO2
WSO2 Open Banking AM
WSO2
WSO2 Identity Server as Key Manager
WSO2
WSO2 API Control Plane
WSO2
WSO2 Universal Gateway
WSO2
WSO2 Traffic Manager
WSO2
WSO2 Enterprise Integrator
WSO2
WSO2 Carbon Identity Entitlement UI
WSO2
WSO2 Carbon Identity Management UI1
WSO2
WSO2 Carbon Identity User Store Configuration UI
WSO2
WSO2 Carbon Registry Profiles UI
WSO2
WSO2 Carbon Registry Properties UI
WSO2
WSO2 Carbon Registry Resources UI
WSO2
WSO2 Carbon Registry Search UI
WSO2
WSO2 Stratos User Interface For Tenant CRUD Operations
WSO2
WSO2 Stratos SSO Redirector UI Component
WSO2
WSO2 Carbon Email Verification UI
WSO2
WSO2 Carbon Event Simulator UI
WSO2
WSO2 Carbon Execution Manager UI
WSO2
WSO2 Carbon Governance Custom Lifecycle Checklist UI
WSO2
WSO2 Carbon Governance Generic Artifact User Interface
WSO2
WSO2 Carbon Governance Life Cycles User Interface
WSO2
WSO2 Carbon Governance WSDL Tool UI
WSO2
WSO2 Carbon New Data Sources UI
WSO2
WSO2 Carbon Registry Info UI2
WSO2
WSO2 Carbon Registry Relations UI
WSO2
WSO2 Carbon Registry Indexing
WSO2
WSO2 Carbon Security UI
WSO2
WSO2 Carbon Component Andes Event UI
WSO2
WSO2 Carbon Component Andes UI1
WSO2
WSO2 Carbon HL7 Business Messaging Store UI
WSO2
WSO2 Carbon Endpoint Editor UI
WSO2
WSO2 Carbon Publish Event Mediator Configuration UI
WSO2
WSO2 Carbon Eventing UI
WSO2
WSO2 Carbon HumanTask UI
WSO2
WSO2 Carbon Logging UI
WSO2
WSO2 Carbon Template Editor UI
WSO2
WSO2 Carbon Command Mediator UI
WSO2
WSO2 Carbon Rule Mediator UI
WSO2
WSO2 Carbon Throttle Mediator UI
WSO2
WSO2 Carbon Tasks Core
WSO2
WSO2 Carbon Rest API Admin UI
WSO2
WSO2 Carbon Sequence Editor UI
WSO2
WSO2 Carbon Task UI
WSO2
WSO2 Carbon Governance
pkg:maven/org.wso2.identity.server/wso2-identity-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Ajax processor in the Carbon console of WSO2 Identity Server does not adequately protect state-changing operations from CSRF attacks. It uses HTTP GET requests for these operations and relies on the SameSite=Lax cookie attribute, which permits cookies to be sent with cross-origin top-level navigation GET requests. This design flaw allows attackers to cause authenticated users' browsers to execute unintended state-altering requests without their consent. The vulnerability affects multiple specific versions of WSO2 Identity Server. There is no official remediation or patch currently documented, and the vulnerability is only exploitable if the affected services are exposed to the public internet.
Potential Impact
An attacker can perform unauthorized state-changing actions on behalf of authenticated users, potentially leading to data modification, account changes, or loss of user control. The vulnerability does not impact confidentiality but affects integrity and availability due to unauthorized changes and possible service disruption. Exploitation requires user interaction and public exposure of the Carbon console, limiting the attack surface.
Mitigation Recommendations
No official patch or fix is currently documented. WSO2 recommends not exposing the Carbon console and related services to the public internet, which effectively mitigates the risk. Organizations should follow this guidance to prevent exploitation. Monitor vendor advisories for any future updates or patches addressing this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WSO2
- Date Reserved
- 2025-11-19T06:17:35.259Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7441c2bf8831d53967ebb2
Added to database: 08/06/2026, 08:11:46 UTC
Last enriched: 08/13/2026, 17:33:09 UTC
Last updated: 09/21/2026, 22:01:28 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.