An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user account is deleted, the system does not automatically remove associated FIDO registration data. If a new user account is later created using the same username, the system may associate the new account with the previously registered FIDO device. This flaw may allow a previously deleted user to authenticate using their FIDO credentials and impersonate the newly created user, resulting in unauthorized access. The vulnerability applies only to deployments that utilize FIDO-based authentication.
Use CWE-287, Wso2 vendor hub and Identity Server product page to widen CVE-2025-0672 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-9312, CVE-2025-6670 and CVE-2025-12107 for nearby disclosures in the same product family.