Junglewise Threat Intelligence

CVE-2026-25138: PYSEC-2026-3053 - Rucio WebUI has Username Enumeration via Login Error Message

CVE-2026-25138 · Severity: low · CVSS 3.1 · Published 2026-07-13

Technologies: rucio-webui (PyPI). Vendors: PyPI.

Executive brief

Rucio WebUI is a web-based user interface for the Rucio distributed data management system. The login endpoint returns different error messages depending on whether a supplied username exists, allowing unauthenticated attackers to discover valid usernames. An attacker could use this to build a list of real accounts for targeted password guessing, credential stuffing, or social engineering campaigns.

Technical details

The vulnerability is an information disclosure flaw (CWE-204: Observable Response Discrepancy) in the /ui/login endpoint. When an invalid username is submitted, the system returns a message stating "Cannot get find any account associated with [username] identity," while a valid username with a wrong password returns "Cannot get auth token. It is possible that the presented identity [username] is not mapped to any Rucio account [username]." An unauthenticated attacker can exploit this behavioral difference to enumerate valid usernames by observing response content. The vulnerability requires no privileges, user interaction, or authentication. Patches are available in versions 35.8.3, 38.5.4, and 39.3.1 or later.

Affected products

  • Rucio WebUI before 35.8.3, 38.5.4, 39.3.1

Timeline

  • 2026-02-25: disclosed
  • 2026-02-25: patched: Patches released: 35.8.3, 38.5.4, 39.3.1

References

Related threats