CVE-2026-25138: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25138 is a username enumeration vulnerability in the Rucio WebUI login endpoint, classified as Username Enumeration via Login Error Message. Rucio is a scientific data management framework developed by CERN. The flaw affects rucio-webui versions prior to 35.8.3, versions 36.0.0rc1 through 38.5.4, and versions 39.0.0rc1 through 39.3.1. It was disclosed on February 25, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, Rucio Advisory).

Technical details

The root cause is an Observable Response Discrepancy (CWE-204) in the /ui/login endpoint of the Rucio WebUI. When a non-existent username is submitted, the response contains the message Cannot get find any account associated with <username> identity, whereas a valid username with an incorrect password returns Cannot get auth token. It is possible that the presented identity <username> is not mapped to any Rucio account. An unauthenticated, remote attacker with no privileges required can exploit this by submitting login requests with candidate usernames and observing the differing error messages to determine account existence. No special preconditions beyond network access to the WebUI are needed (Github Advisory, Rucio Advisory).

Impact

The primary impact is a low-level confidentiality breach: an unauthenticated attacker can compile a list of valid Rucio usernames without any authentication. While there is no direct integrity or availability impact, the enumerated usernames can serve as a foundation for targeted password-guessing attacks, credential stuffing campaigns, or social engineering against users of the Rucio scientific data management platform — which may manage large volumes of sensitive research data. The vulnerability does not by itself grant access to data or accounts (Github Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.077% (23rd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The technique is trivially executable with basic HTTP tooling (e.g., curl or Burp Suite) given the clear behavioral difference in error messages, but no weaponized tooling has been publicly identified (Github Advisory, Rucio Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Rucio WebUI instances running vulnerable versions (< 35.8.3, 36.0.0rc1–38.5.4, or 39.0.0rc1–39.3.1) using network scanning or Shodan.
  2. Baseline request: Send a POST request to /ui/login with a clearly non-existent username (e.g., a random string) and any password. Observe the response body for the message Cannot get find any account associated with <username> identity.
  3. Enumerate usernames: Iterate through a wordlist of candidate usernames (e.g., common names, institutional usernames, or known Rucio account patterns), sending a login request for each.
  4. Identify valid accounts: If the response contains Cannot get auth token. It is possible that the presented identity <username> is not mapped to any Rucio account, the username exists in the system.
  5. Compile valid username list: Record all usernames that produce the second error message for use in subsequent targeted password attacks, credential stuffing, or social engineering campaigns (Github Advisory, Rucio Advisory).

Indicators of compromise

  • Network: High volume of POST requests to /ui/login from a single IP or small IP range, especially with varying usernames and consistent (likely invalid) passwords.
  • Logs: Web server or application logs showing repeated failed login attempts to /ui/login with many different usernames but no successful authentications; responses alternating between the two distinct error message types.
  • Behavioral: Login attempts using a pattern consistent with wordlist iteration (sequential or dictionary-based usernames); unusually high login failure rate without corresponding successful logins from the same source (Github Advisory).

Mitigation and workarounds

Upgrade rucio-webui to one of the patched versions: 35.8.3, 38.5.4, or 39.3.1, all released on February 25, 2026. The fix standardizes the login error response to a generic authentication failure message regardless of whether the username exists. As an interim workaround, implement rate limiting or login throttling on the /ui/login endpoint to reduce the feasibility of automated enumeration. Operators should also consider deploying a web application firewall (WAF) rule to detect and block high-frequency login attempts from single sources (Rucio Advisory, Release 35.8.3, Release 38.5.4, Release 39.3.1).

Community reactions

The vulnerability was reported by researcher d-woosley and published by Rucio maintainer bziemons via GitHub Security Advisories on February 25, 2026. The advisory was simultaneously bundled with five other WebUI security fixes (multiple XSS vulnerabilities), suggesting a coordinated security audit of the Rucio WebUI component. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified (Rucio Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management