Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2025-5802PATCHED
wso2 · api manager

Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery

Description

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.

Affected Products

VendorProductVersions
wso2api manager3.1.0, 3.2.0, 3.2.0, 3.2.1, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.5.0, 4.6.0, 4.5.0, 4.6.0, 4.5.0, 4.6.0, 5.10.0, 5.11.0, 6.0.0, 6.1.0, 6.1.0, 7.0.0, 7.1.0, 7.2.0, 5.10.0, 2.0.0, 2.0.0, 5.17.5, 5.18.187, 5.23.8, 5.25.92, 7.0.78, 5.17.5, 5.18.187

References

  • https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4227/(vendor-advisory)

Related News (1 articles)

Tier C
VulDB12d ago
CVE-2025-5802 | WSO2 API Manager Self-Registration Flow information disclosure
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.1.0.3543.2.0.4583.2.0.4783.2.1.964.0.0.3794.1.0.2624.2.0.2004.3.0.1124.4.0.724.5.0.554.6.0.174.5.0.564.6.0.184.5.0.545.10.0.3835.11.0.4306.0.0.2576.1.0.2346.1.0.2577.0.0.1337.1.0.417.2.0.35.10.0.3742.0.0.4032.0.0.4235.17.5.3325.18.187.3305.23.8.2135.25.92.1677.0.78.162x
CWECWE-203
PublishedSep 15, 2026
Last enriched12d ago
Trending Score7
Source articles1
Independent1
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Trending: 55
HIGHCVE-2026-19515
OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution
Trending: 7
LOWCVE-2025-13166
Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery
Trending: 4
MEDIUMCVE-2026-4103
Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution
Trending: 4
MEDIUMCVE-2026-3096
Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
Trending: 3

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 15, 2026
Discovered by ZDM
Sep 15, 2026
Patch Available
Sep 15, 2026