Impact
The flaw resides in the self‑registration flow of several WSO2 products, where the system accepts user‑supplied usernames and returns a specific error message when a username is already taken. This explicit indication allows an attacker to confirm whether a given account exists, thereby enabling username enumeration. The potential impact includes facilitating brute‑force credential attacks, phishing, and social engineering campaigns that rely on knowing valid usernames, even though the vulnerability does not directly grant authentication bypass or data compromise. The weakness corresponds to CWE‑203, Information Exposure.
Affected Systems
The vulnerability affects WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon Identity Application Authentication Framework, WSO2 Carbon Identity Management Endpoint Util, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. No specific version information is disclosed in the advisory.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the publicly accessible self‑registration endpoint, as the system responds to any registration attempt without prior authentication, enabling enumeration from any location with network access to the service.
OpenCVE Enrichment