Executive brief
Rucio WebUI is a web-based user interface for the Rucio distributed data management system. The login endpoint returns different error messages depending on whether a supplied username exists, allowing unauthenticated attackers to discover valid usernames. An attacker could use this to build a list of real accounts for targeted password guessing, credential stuffing, or social engineering campaigns.
Technical details
The vulnerability is an information disclosure flaw (CWE-204: Observable Response Discrepancy) in the /ui/login endpoint. When an invalid username is submitted, the system returns a message stating "Cannot get find any account associated with [username] identity," while a valid username with a wrong password returns "Cannot get auth token. It is possible that the presented identity [username] is not mapped to any Rucio account [username]." An unauthenticated attacker can exploit this behavioral difference to enumerate valid usernames by observing response content. The vulnerability requires no privileges, user interaction, or authentication. Patches are available in versions 35.8.3, 38.5.4, and 39.3.1 or later.
Affected products
- Rucio WebUI before 35.8.3, 38.5.4, 39.3.1
Timeline
- 2026-02-25: disclosed
- 2026-02-25: patched: Patches released: 35.8.3, 38.5.4, 39.3.1