
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13736 is a username enumeration vulnerability (Observable Discrepancy) in multiple WSO2 products that arises when the Multi-Attribute Login feature is enabled. The login interface inconsistently masks the existence of user accounts: for valid users, the server resolves and displays their canonical username, while for non-existent users it echoes the original input — regardless of the validate_username configuration. Affected products include WSO2 Identity Server (5.10.0–7.2.x), WSO2 API Manager (3.1.0–4.0.x), WSO2 Identity Server as Key Manager (5.10.x), WSO2 Open Banking IAM (2.0.x), and WSO2 Open Banking AM (2.0.x). It was published on August 6, 2026, with a CVSS v3.1 base score of 3.7 (Low) (GitHub Advisory, WSO2 Advisory).
The root cause is classified as CWE-203 (Observable Discrepancy): the application behaves differently depending on whether a submitted login identifier corresponds to a real account, leaking account existence information to unauthenticated observers. When Multi-Attribute Login is active, the server resolves a valid user's canonical username and returns it in the response, whereas an invalid identifier is simply echoed back — creating a detectable behavioral difference. This attack requires no authentication or special privileges and is exploitable remotely over the network, though it carries high attack complexity (AC:H) per the CVSS scoring. No technical write-ups or public proof-of-concept code have been identified at this time (GitHub Advisory, WSO2 Advisory).
The primary impact is limited confidentiality loss: an unauthenticated attacker can enumerate valid usernames within the affected WSO2 systems by observing differential login responses. While this does not directly compromise system integrity or availability, the disclosed usernames can significantly increase the effectiveness of downstream attacks such as brute force credential stuffing, targeted phishing campaigns, and social engineering tactics aimed at compromising user accounts or extracting sensitive data (GitHub Advisory, WSO2 Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2025-13736. The EPSS score is approximately 0.171% (7th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment confirms no known exploitation and non-automatable attack conditions (GitHub Advisory, WSO2 Advisory).
firstname.lastname@domain.com, flastname@domain.com) suggesting automated enumeration rather than organic user activity.WSO2 has released patched versions addressing this vulnerability: Identity Server (5.10.0.380, 5.11.0.427, 6.0.0.254, 6.1.0.255, 7.0.0.132, 7.1.0.40, 7.2.0.2), API Manager (3.1.0.351, 3.2.0.455, 4.0.0.375), Identity Server as Key Manager (5.10.0.371), Open Banking IAM (2.0.0.420), and Open Banking AM (2.0.0.400). Organizations should upgrade to the applicable patched version immediately. As interim mitigations, consider disabling Multi-Attribute Login if not required, and implement rate limiting and account lockout policies on login endpoints to reduce the effectiveness of enumeration-enabled brute force attacks (WSO2 Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."