CVE-2025-13166
Received Received - Intake

Username Enumeration in SMS OTP Authentication Flow

Vulnerability report for CVE-2025-13166, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: WSO2 LLC

Description

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically tied to this condition. The discovery of these usernames can facilitate subsequent brute force attacks, social engineering attempts, and information leakage, potentially leading to reputational damage, loss of customer trust, and regulatory non-compliance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wso2 identity_server From 7.2.0 (inc) to 7.3.0 (exc)
wso2 identity_server From 7.1.0 (inc) to 7.2.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the SMS OTP flow not properly handling error messages. Attackers can exploit this to determine if a username is registered by observing the system's responses during OTP initiation. The flaw specifically affects accounts without a configured mobile number.

Detection Guidance

To detect this vulnerability, monitor SMS OTP flow responses for inconsistent error messages when invalid usernames are entered. Test with both registered and unregistered accounts to observe differences in responses. Check if the system reveals valid usernames based on mobile number configuration status.

Impact Analysis

This vulnerability can lead to username enumeration, enabling attackers to identify valid accounts. This increases risks of brute force attacks, social engineering, and information leakage. It may result in phishing attempts, reputational damage, and potential legal or financial consequences.

Compliance Impact

The vulnerability can lead to regulatory non-compliance due to information leakage and potential breaches of user data. This may result in legal penalties, reputational harm, and loss of customer trust, particularly under standards like GDPR and HIPAA.

Mitigation Strategies

Apply the public fix provided by WSO2 or update to the latest unaffected version. For version 7.2.0, update to level 2 or higher. For version 7.1.0, update to level 40 or higher. If using a support subscription, contact WSO2 for specific guidance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-13166. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart