CVE-2025-5802
Received Received - Intake

Username Enumeration in Self-Registration Flow

Vulnerability report for CVE-2025-5802, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: WSO2 LLC

Description

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
wso2 api_control_plane 4.6.0
wso2 api_control_plane 4.5.0
wso2 api_manager From 3.1.0 (inc) to 4.6.0 (inc)
wso2 identity_server From 5.10.0 (inc) to 7.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows attackers to discover valid usernames by exploiting error messages during self-registration. When a user tries to register with an existing username, the system reveals whether the username is already in use, enabling username enumeration.

Detection Guidance

To detect this vulnerability, monitor the self-registration flow for error messages indicating a username already exists. Test by attempting to register with multiple usernames and observe if responses reveal valid accounts. Check WSO2 product logs for self-registration errors or unusual activity.

Impact Analysis

This vulnerability can lead to increased risks such as brute force attacks, social engineering, targeted phishing campaigns, or information leakage by exposing valid usernames in the system.

Mitigation Strategies

Disable the 'Display message if username unavailable' option in self-registration settings. Apply available patches or updates for affected WSO2 products. For community users, apply GitHub pull request fixes. For subscribers, update to specified versions as per advisory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-5802. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart