
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-5802 is a username enumeration (Observable Discrepancy) vulnerability in multiple WSO2 products that allows unauthenticated remote attackers to discover valid usernames via the self-registration flow. When a registration attempt is made with an already-existing username, the system returns an explicit error message confirming the username is in use, enabling systematic enumeration. Affected products include WSO2 API Manager (3.1.0–4.6.0), WSO2 Identity Server (5.10.0–7.2.0), WSO2 API Control Plane (4.5.0–4.6.0), WSO2 Universal Gateway (4.5.0–4.6.0), WSO2 Traffic Manager (4.5.0–4.6.0), WSO2 Open Banking AM/IAM (2.0.0), and WSO2 Identity Server as Key Manager (5.10.0), across numerous specific build versions. It was published on September 15, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, WSO2 Advisory).
The root cause is classified as CWE-203 (Observable Discrepancy): the self-registration endpoint behaves differently depending on whether a submitted username already exists, and this behavioral difference is exposed to the requester via a distinct error message. An unauthenticated attacker can send HTTP registration requests with candidate usernames and observe the response — a specific error message confirms username existence, while a different response indicates the username is available. No authentication, special privileges, or user interaction is required, and the attack can be fully automated. The vulnerability resides in the org.wso2.carbon.identity.mgt.endpoint.util and org.wso2.carbon.identity.application.authentication.framework components (GitHub Advisory, WSO2 Advisory).
Successful exploitation results in limited confidentiality impact: an attacker can compile a list of valid usernames registered in the affected WSO2 system without any authentication. While there is no direct integrity or availability impact, the enumerated usernames can serve as a foundation for follow-on attacks including credential brute force, targeted phishing, and social engineering campaigns against identified users. The attack is automatable and network-accessible, making large-scale enumeration feasible (GitHub Advisory, WSO2 Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.33%, placing it in the 17th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment notes the attack is automatable with no exploitation currently observed. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.
/accountrecoveryendpoint/register.do or equivalent registration URL on the target WSO2 instance.requests, ffuf, or Burp Suite Intruder) to iterate through large username lists and collect confirmed valid usernames for use in subsequent brute force, phishing, or social engineering attacks (GitHub Advisory, WSO2 Advisory)./accountrecoveryendpoint/register.do) from a single IP or small IP range in a short time window; sequential or pattern-based username submissions.WSO2 has released patched builds for all affected products. Key fixed versions include: WSO2 API Manager 3.1.0.354, 3.2.0.458/478, 3.2.1.96, 4.0.0.379, 4.1.0.262, 4.2.0.200, 4.3.0.112, 4.4.0.72, 4.5.0.55, 4.6.0.17; WSO2 Identity Server 5.10.0.383, 5.11.0.430, 6.0.0.257, 6.1.0.257, 7.0.0.133, 7.1.0.41, 7.2.0.3; and corresponding fixes for API Control Plane, Universal Gateway, Traffic Manager, Open Banking AM/IAM, and Identity Server as Key Manager. As interim workarounds, administrators should implement rate limiting on the self-registration endpoint to reduce enumeration efficiency and configure generic error messages that do not distinguish between "username taken" and other registration failures. Upgrading to a patched version is the recommended long-term solution (WSO2 Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."