Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-5802
WSO2 API Manager vulnerability analysis and mitigation

Overview

CVE-2025-5802 is a username enumeration (Observable Discrepancy) vulnerability in multiple WSO2 products that allows unauthenticated remote attackers to discover valid usernames via the self-registration flow. When a registration attempt is made with an already-existing username, the system returns an explicit error message confirming the username is in use, enabling systematic enumeration. Affected products include WSO2 API Manager (3.1.0–4.6.0), WSO2 Identity Server (5.10.0–7.2.0), WSO2 API Control Plane (4.5.0–4.6.0), WSO2 Universal Gateway (4.5.0–4.6.0), WSO2 Traffic Manager (4.5.0–4.6.0), WSO2 Open Banking AM/IAM (2.0.0), and WSO2 Identity Server as Key Manager (5.10.0), across numerous specific build versions. It was published on September 15, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, WSO2 Advisory).

Technical details

The root cause is classified as CWE-203 (Observable Discrepancy): the self-registration endpoint behaves differently depending on whether a submitted username already exists, and this behavioral difference is exposed to the requester via a distinct error message. An unauthenticated attacker can send HTTP registration requests with candidate usernames and observe the response — a specific error message confirms username existence, while a different response indicates the username is available. No authentication, special privileges, or user interaction is required, and the attack can be fully automated. The vulnerability resides in the org.wso2.carbon.identity.mgt.endpoint.util and org.wso2.carbon.identity.application.authentication.framework components (GitHub Advisory, WSO2 Advisory).

Impact

Successful exploitation results in limited confidentiality impact: an attacker can compile a list of valid usernames registered in the affected WSO2 system without any authentication. While there is no direct integrity or availability impact, the enumerated usernames can serve as a foundation for follow-on attacks including credential brute force, targeted phishing, and social engineering campaigns against identified users. The attack is automatable and network-accessible, making large-scale enumeration feasible (GitHub Advisory, WSO2 Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.33%, placing it in the 17th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment notes the attack is automatable with no exploitation currently observed. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing WSO2 API Manager, Identity Server, or related product instances using tools like Shodan or Censys, targeting versions within the affected ranges.
  2. Locate the self-registration endpoint: Navigate to the self-registration flow, typically accessible at a path such as /accountrecoveryendpoint/register.do or equivalent registration URL on the target WSO2 instance.
  3. Submit registration requests with candidate usernames: Send HTTP POST requests to the registration endpoint with a list of candidate usernames (e.g., from common username wordlists or known organizational email patterns).
  4. Observe differential responses: Analyze the HTTP responses — an error message explicitly stating the username is already in use confirms the username exists; a different response (e.g., proceeding with registration or a generic error) indicates the username is not registered.
  5. Compile valid username list: Automate the process using scripting tools (e.g., Python requests, ffuf, or Burp Suite Intruder) to iterate through large username lists and collect confirmed valid usernames for use in subsequent brute force, phishing, or social engineering attacks (GitHub Advisory, WSO2 Advisory).

Indicators of compromise

  • Network: High volume of HTTP POST requests to the self-registration endpoint (e.g., /accountrecoveryendpoint/register.do) from a single IP or small IP range in a short time window; sequential or pattern-based username submissions.
  • Logs: WSO2 access logs showing repeated registration attempts with varying usernames, particularly with consistent error responses indicating username conflicts; unusual spike in registration endpoint traffic outside business hours.
  • Application Behavior: Elevated rate of "username already exists" error responses from the self-registration flow compared to baseline; registration attempts using usernames matching known employee or admin account patterns.

Mitigation and workarounds

WSO2 has released patched builds for all affected products. Key fixed versions include: WSO2 API Manager 3.1.0.354, 3.2.0.458/478, 3.2.1.96, 4.0.0.379, 4.1.0.262, 4.2.0.200, 4.3.0.112, 4.4.0.72, 4.5.0.55, 4.6.0.17; WSO2 Identity Server 5.10.0.383, 5.11.0.430, 6.0.0.257, 6.1.0.257, 7.0.0.133, 7.1.0.41, 7.2.0.3; and corresponding fixes for API Control Plane, Universal Gateway, Traffic Manager, Open Banking AM/IAM, and Identity Server as Key Manager. As interim workarounds, administrators should implement rate limiting on the self-registration endpoint to reduce enumeration efficiency and configure generic error messages that do not distinguish between "username taken" and other registration failures. Upgrading to a patched version is the recommended long-term solution (WSO2 Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related WSO2 API Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5430CRITICAL10
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-1728CRITICAL9.8
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2025-12737HIGH8.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:identity_server
NoYesSep 03, 2026
CVE-2026-3416HIGH7.5
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesSep 03, 2026
CVE-2025-5802MEDIUM5.3
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management