CVE-2025-13736Low· 3.7▾ SunlitWhen Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration.
The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
api_manager >= 3.1.0, < 3.1.0.351api_manager >= 3.2.0, < 3.2.0.455api_manager >= 4.0.0, < 4.0.0.375identity_server >= 5.10.0, < 5.10.0.380identity_server >= 5.11.0, < 5.11.0.427identity_server >= 6.0.0, < 6.0.0.254identity_server >= 6.1.0, < 6.1.0.255identity_server >= 7.0.0, < 7.0.0.132identity_server >= 7.1.0, < 7.1.0.40identity_server >= 7.2.0, < 7.2.0.2identity_server_as_key_manager >= 5.10.0, < 5.10.0.371open_banking_am >= 2.0.0, < 2.0.0.400open_banking_iam >= 2.0.0, < 2.0.0.420Upgrade past the affected range:
api_manager 4.0.0.375identity_server 7.2.0.2identity_server_as_key_manager 5.10.0.371open_banking_am 2.0.0.400open_banking_iam 2.0.0.420Connected by shared product, vendor, weakness, or advisory.
CVE-2025-5802Medium· 5.3The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence
CVE-2025-13166Low· 3.7The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …
CVE-2025-10890Critical· 9.1Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page
CVE-2020-3585Medium· 5.3A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain ac…
CVE-2025-15039Critical· 9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured
CVE-2025-13909Medium· 4.3The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators