Description
The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use.

This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Account Discovery
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the self‑registration flow of several WSO2 products, where the system accepts user‑supplied usernames and returns a specific error message when a username is already taken. This explicit indication allows an attacker to confirm whether a given account exists, thereby enabling username enumeration. The potential impact includes facilitating brute‑force credential attacks, phishing, and social engineering campaigns that rely on knowing valid usernames, even though the vulnerability does not directly grant authentication bypass or data compromise. The weakness corresponds to CWE‑203, Information Exposure.

Affected Systems

The vulnerability affects WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon Identity Application Authentication Framework, WSO2 Carbon Identity Management Endpoint Util, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. No specific version information is disclosed in the advisory.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the publicly accessible self‑registration endpoint, as the system responds to any registration attempt without prior authentication, enabling enumeration from any location with network access to the service.

Generated by OpenCVE AI on September 17, 2026 at 18:27 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4227/#solution


OpenCVE Recommended Actions

  • Apply the security patch for the affected WSO2 products following the instructions in the WSO2 security advisory linked above.
  • If the patch cannot be applied immediately, modify the configuration to suppress detailed error messages for existing usernames or restrict access to the self‑registration endpoint to trusted networks.
  • Enable logging and alerting for repeated failed registration attempts to detect and respond to enumeration activity.

Generated by OpenCVE AI on September 17, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.
Title Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery
Weaknesses CWE-203
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-09-15T12:49:19.401Z

Reserved: 2025-06-06T09:33:38.579Z

Link: CVE-2025-5802

cve-icon Vulnrichment

Updated: 2026-09-15T12:49:16.517Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T10:17:02.640

Modified: 2026-09-18T19:13:15.430

Link: CVE-2025-5802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses