Account Enumeration Vulnerability in WSO2 Identity Server
CVE-2025-13736
3.7LOW
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2025-13736?
The vulnerability in WSO2 Identity Server arises from the Multi-Attribute Login feature, which inadequately masks the existence of user accounts. When this feature is enabled, valid users' canonical usernames are displayed, while users that do not exist receive feedback echoing their input. This inconsistency can lead to unauthorized reveals of valid usernames, increasing susceptibility to brute force attacks and social engineering schemes. Attackers can exploit this knowledge to enhance the effectiveness of phishing campaigns or to launch targeted efforts aiming to access sensitive information and breach user accounts.
Affected Version(s)
WSO2 API Manager 3.1.0 < 3.1.0.351
WSO2 API Manager 3.2.0 < 3.2.0.455
WSO2 API Manager 4.0.0 < 4.0.0.375
