Answer in brief
CVE-2025-13736 records a Low severity (CVSS 3.7) vulnerability in Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Manager (generic), WSO2/WSO2 Identity Server (generic), WSO2/WSO2 Identity Server as Key Manager (generic), WSO2/WSO2 Open Banking AM (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 3.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Manager (generic), WSO2/WSO2 Identity Server (generic), WSO2/WSO2 Identity Server as Key Manager (generic), WSO2/WSO2 Open Banking AM (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Managergeneric | >=3.1.0 <3.1.0.351 || >=3.2.0 <3.2.0.455 || >=4.0.0 <4.0.0.375 | 3.1.0.351, 3.2.0.455, 4.0.0.375 |
| WSO2/WSO2 Identity Servergeneric | >=5.10.0 <5.10.0.380 || >=5.11.0 <5.11.0.427 || >=6.0.0 <6.0.0.254 || >=6.1.0 <6.1.0.255 || >=7.0.0 <7.0.0.132 || >=7.1.0 <7.1.0.40 || >=7.2.0 <7.2.0.2 | 5.10.0.380, 5.11.0.427, 6.0.0.254, 6.1.0.255, 7.0.0.132, 7.1.0.40, 7.2.0.2 |
| WSO2/WSO2 Identity Server as Key Managergeneric | >=5.10.0 <5.10.0.371 | 5.10.0.371 |
| WSO2/WSO2 Open Banking AMgeneric | >=2.0.0 <2.0.0.400 | 2.0.0.400 |
| WSO2/WSO2 Open Banking IAMgeneric | >=2.0.0 <2.0.0.420 | 2.0.0.420 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration. The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-13736 records a Low severity (CVSS 3.7) vulnerability in Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Manager (generic), WSO2/WSO2 Identity Server (generic), WSO2/WSO2 Identity Server as Key Manager (generic), WSO2/WSO2 Open Banking AM (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 3.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Manager (generic), WSO2/WSO2 Identity Server (generic), WSO2/WSO2 Identity Server as Key Manager (generic), WSO2/WSO2 Open Banking AM (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Managergeneric | >=3.1.0 <3.1.0.351 || >=3.2.0 <3.2.0.455 || >=4.0.0 <4.0.0.375 | 3.1.0.351, 3.2.0.455, 4.0.0.375 |
| WSO2/WSO2 Identity Servergeneric | >=5.10.0 <5.10.0.380 || >=5.11.0 <5.11.0.427 || >=6.0.0 <6.0.0.254 || >=6.1.0 <6.1.0.255 || >=7.0.0 <7.0.0.132 || >=7.1.0 <7.1.0.40 || >=7.2.0 <7.2.0.2 | 5.10.0.380, 5.11.0.427, 6.0.0.254, 6.1.0.255, 7.0.0.132, 7.1.0.40, 7.2.0.2 |
| WSO2/WSO2 Identity Server as Key Managergeneric | >=5.10.0 <5.10.0.371 | 5.10.0.371 |
| WSO2/WSO2 Open Banking AMgeneric | >=2.0.0 <2.0.0.400 | 2.0.0.400 |
| WSO2/WSO2 Open Banking IAMgeneric | >=2.0.0 <2.0.0.420 | 2.0.0.420 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays their canonical username, while for non-existent users, it echoes the original input. This occurs regardless of the validate_username configuration. The discovery of valid usernames can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Attackers can leverage this information to craft more effective phishing campaigns or social engineering tactics to compromise user accounts or extract sensitive data.
Quoted source text, attributed separately from HOL analysis.