The absence of automatic expiration for OTPs grants attackers an unlimited timeframe to attempt guessing the correct code. A successful brute force attack can lead to an MFA bypass, resulting in the unauthorized takeover of a user's account and compromising the security and privacy of both the individual and the system.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3149/#solution
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious actors to conduct brute force attacks by repeatedly guessing the OTP. The absence of automatic expiration for OTPs grants attackers an unlimited timeframe to attempt guessing the correct code. A successful brute force attack can lead to an MFA bypass, resulting in the unauthorized takeover of a user's account and compromising the security and privacy of both the individual and the system. | |
| Title | Potential brute force vulnerability due to non-expiring SMS OTPs | |
| First Time appeared |
Wso2
Wso2 wso2 Identity Server |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wso2
Wso2 wso2 Identity Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-10-08T00:09:52.353Z
Reserved: 2024-08-23T14:52:53.493Z
Link: CVE-2024-8122
No data.
Status : Deferred
Published: 2026-10-08T01:16:32.037
Modified: 2026-10-08T01:16:32.183
Link: CVE-2024-8122
No data.
OpenCVE Enrichment
No data.