Executive brief
WSO2 Identity Server, a tool used for managing user identities and access, contains a flaw in its email-based login process. An attacker can use this flaw to verify whether specific email addresses or usernames are registered in the system. This information can be used to launch targeted phishing campaigns or brute-force login attempts against known valid accounts.
Technical details
A username enumeration vulnerability exists in WSO2 Identity Server due to an observable response discrepancy (CWE-204) in the email OTP flow. Specifically, the feature that checks user account lock states does not properly validate or normalize responses for existing versus non-existing users. A remote, unauthenticated attacker can exploit this by sending crafted requests to the email OTP endpoint to identify valid registered accounts. This information leakage facilitates subsequent brute-force or social engineering attacks. Fixes are available via GitHub pull requests for community users and specific update levels for support subscribers.
Affected products
- WSO2 Identity Server 5.10.0, 5.11.0, 6.0.0, 6.1.0, 7.0.0
- WSO2 Identity Server as Key Manager 5.10.0
- WSO2 Open Banking IAM 2.0.0
Timeline
- 2026-01-26: advisory: Initial advisory published by WSO2
- 2026-05-11: disclosed: CVE published to NVD