Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
3.7
CVE-2025-13166PATCHED
wso2 · wso2 identity server

Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery

Description

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically tied to this condition. The discovery of these usernames can facilitate subsequent brute force attacks, social engineering attempts, and information leakage, potentially leading to reputational damage, loss of customer trust, and regulatory non-compliance.

Affected Products

VendorProductVersions
wso2wso2 identity server7.1.0, 7.2.0

References

  • https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4353/(vendor-advisory)

Related News (1 articles)

Tier C
VulDB12d ago
CVE-2025-13166 | WSO2 Identity Server up to 7.0.x information exposure
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.13.7 LOW
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
7.1.0.407.2.0.2
CWECWE-203
PublishedSep 15, 2026
Last enriched12d ago
Trending Score4
Source articles1
Independent1
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Trending: 55
MEDIUMCVE-2025-5802
Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery
Trending: 7
HIGHCVE-2026-19515
OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution
Trending: 7
MEDIUMCVE-2026-4103
Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution
Trending: 4
MEDIUMCVE-2026-3096
Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
Trending: 3

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 15, 2026
Discovered by ZDM
Sep 15, 2026
Patch Available
Sep 15, 2026