CVE-2025-13736
WSO2 API Manager vulnerability analysis and mitigation

Overview

CVE-2025-13736 is a username enumeration vulnerability (Observable Discrepancy) in multiple WSO2 products that arises when the Multi-Attribute Login feature is enabled. The login interface inconsistently masks the existence of user accounts: for valid users, the server resolves and displays their canonical username, while for non-existent users it echoes the original input — regardless of the validate_username configuration. Affected products include WSO2 Identity Server (5.10.0–7.2.x), WSO2 API Manager (3.1.0–4.0.x), WSO2 Identity Server as Key Manager (5.10.x), WSO2 Open Banking IAM (2.0.x), and WSO2 Open Banking AM (2.0.x). It was published on August 6, 2026, with a CVSS v3.1 base score of 3.7 (Low) (GitHub Advisory, WSO2 Advisory).

Technical details

The root cause is classified as CWE-203 (Observable Discrepancy): the application behaves differently depending on whether a submitted login identifier corresponds to a real account, leaking account existence information to unauthenticated observers. When Multi-Attribute Login is active, the server resolves a valid user's canonical username and returns it in the response, whereas an invalid identifier is simply echoed back — creating a detectable behavioral difference. This attack requires no authentication or special privileges and is exploitable remotely over the network, though it carries high attack complexity (AC:H) per the CVSS scoring. No technical write-ups or public proof-of-concept code have been identified at this time (GitHub Advisory, WSO2 Advisory).

Impact

The primary impact is limited confidentiality loss: an unauthenticated attacker can enumerate valid usernames within the affected WSO2 systems by observing differential login responses. While this does not directly compromise system integrity or availability, the disclosed usernames can significantly increase the effectiveness of downstream attacks such as brute force credential stuffing, targeted phishing campaigns, and social engineering tactics aimed at compromising user accounts or extracting sensitive data (GitHub Advisory, WSO2 Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2025-13736. The EPSS score is approximately 0.171% (7th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment confirms no known exploitation and non-automatable attack conditions (GitHub Advisory, WSO2 Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing WSO2 Identity Server, API Manager, or related product instances with Multi-Attribute Login enabled, using tools like Shodan or Censys targeting known WSO2 login endpoints.
  2. Probe the login interface: Submit login requests using various identifiers (e.g., email addresses, phone numbers, or usernames) to the Multi-Attribute Login endpoint.
  3. Observe differential responses: Compare server responses — if the server returns a resolved canonical username, the account exists; if it echoes the original input unchanged, the account does not exist.
  4. Build a valid username list: Iterate over a list of candidate identifiers (e.g., common usernames, email formats from OSINT) to compile a list of confirmed valid accounts.
  5. Leverage enumerated usernames: Use the confirmed account list to conduct targeted brute force attacks, credential stuffing, or craft convincing phishing/social engineering campaigns against identified users (GitHub Advisory, WSO2 Advisory).

Indicators of compromise

  • Network: High volume of login attempts to WSO2 login endpoints from a single IP or small IP range, particularly with varied usernames/identifiers and no successful authentications.
  • Logs: WSO2 access logs showing repeated failed login requests with different usernames but consistent patterns (e.g., sequential email formats, dictionary-based usernames); unusual spikes in login endpoint traffic outside business hours.
  • Behavioral: Login attempts that systematically cycle through username formats (e.g., firstname.lastname@domain.com, flastname@domain.com) suggesting automated enumeration rather than organic user activity.

Mitigation and workarounds

WSO2 has released patched versions addressing this vulnerability: Identity Server (5.10.0.380, 5.11.0.427, 6.0.0.254, 6.1.0.255, 7.0.0.132, 7.1.0.40, 7.2.0.2), API Manager (3.1.0.351, 3.2.0.455, 4.0.0.375), Identity Server as Key Manager (5.10.0.371), Open Banking IAM (2.0.0.420), and Open Banking AM (2.0.0.400). Organizations should upgrade to the applicable patched version immediately. As interim mitigations, consider disabling Multi-Attribute Login if not required, and implement rate limiting and account lockout policies on login endpoints to reduce the effectiveness of enumeration-enabled brute force attacks (WSO2 Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related WSO2 API Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5430CRITICAL10
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-1728CRITICAL9.8
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2025-15039CRITICAL9.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-0637MEDIUM4.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:identity_server
NoYesAug 06, 2026
CVE-2025-13736LOW3.7
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management