Description
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration.

The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
Published: 2026-08-06
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

When Multi-Attribute Login is enabled in WSO2 products, the login endpoint leaks whether a username exists. For valid accounts the canonical username is returned, while for invalid accounts the original input is echoed. This unintended disclosure allows an attacker to enumerate legitimate user accounts, increasing the effectiveness of brute‑force attempts, phishing campaigns, and social engineering. The vulnerability itself is an information‑disclosure flaw, classified as CWE‑203.

Affected Systems

The flaw affects multiple WSO2 products, including WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, and WSO2 Open Banking IAM. It is triggered when the Multi‑Attribute Login feature is enabled; no specific version details are listed, so the issue may exist across all current releases until addressed in the vendor advisories.

Risk and Exploitability

The CVSS score of 3.7 indicates a low‑severity disclosure risk, but based on the description the likely attack vector is remote through the public login interface, making it accessible to anyone who can reach the service. The EPSS score is not available, and the vulnerability is not in the CISA KEV catalog, suggesting limited evidence of exploitation in the wild. Nevertheless, the attacker’s ability to enumerate usernames can lower the effort required for subsequent credential‑guessing or social engineering attacks, implying moderate operational risk for organizations that rely on these products.

Generated by OpenCVE AI on August 6, 2026 at 09:52 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4013/#solution


OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade as described in the official WSO2 solution documentation (https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4013/#solution).
  • If upgrading or patching immediately is not possible, disable the Multi‑Attribute Login feature or enforce stricter input validation so that the response does not reveal whether a username exists.
  • Implement login rate limiting, account lockout policies, and monitor authentication logs for patterns of enumeration attempts to reduce the effectiveness of remaining disclosure vectors.

Generated by OpenCVE AI on August 6, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2
Wso2 wso2 Api Manager
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam
Vendors & Products Wso2
Wso2 wso2 Api Manager
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam

Thu, 06 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration. The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
Title Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery
Weaknesses CWE-203
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wso2 Wso2 Api Manager Wso2 Identity Server Wso2 Identity Server As Key Manager Wso2 Open Banking Am Wso2 Open Banking Iam
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-06T07:33:03.994Z

Reserved: 2025-11-26T04:51:38.625Z

Link: CVE-2025-13736

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T10:45:03Z

Weaknesses