CVE-2024-0391 Details
Description
The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-force and social engineering attacks. Attackers can leverage this information to craft targeted phishing campaigns or other malicious activities aimed at tricking users into divulging sensitive data, potentially damaging the organization's reputation and leading to regulatory non-compliance and financial consequences.
A vulnerability exists in the email OTP flow of WSO2 Identity Server (versions 7.0.0, 6.1.0, 6.0.0, 5.11.0, and 5.10.0), WSO2 Identity Server as Key Manager 5.10.0, and WSO2 Open Banking IAM 2.0.0. The issue arises because the feature that checks user account lock states does not properly validate user input. This flaw allows attackers to infer the existence of registered user accounts, potentially leading to brute-force and social engineering attacks. Knowledge of valid usernames can be exploited to create targeted phishing campaigns or other malicious activities aimed at tricking users into revealing sensitive information, which could harm the organization's reputation and result in regulatory non-compliance and financial repercussions.
Users of WSO2 Identity Server can update to version 7.0.0 (update level 131), 6.1.0 (update level 254), 6.0.0 (update level 253), 5.11.0 (update levels 426 or 431) or 5.10.0 (update level 379). WSO2 Identity Server as Key Manager users can update to version 5.10.0 (update level 267). WSO2 Open Banking IAM users can update to version 2.0.0 (update level 318). Community users can apply the public fix available on GitHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3115/ | WSO2 LLC | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-204 | Observable Response Discrepancy | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 identity server | >= 5.10.0, < 5.10.0.379 >= 5.11.0, < 5.11.0.426 >= 6.0.0, < 6.0.0.253 >= 6.1.0, < 6.1.0.254 >= 7.0.0, < 7.0.0.131 |
CPE
Remediation
| |
| wso2 identity server as key manager | >= 5.10.0, < 5.10.267 |
CPE
Remediation
| |
| wso2 open banking iam | >= 2.0.0, < 2.0.0.318 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | WSO2 LLC |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | New CVE Received | WSO2 LLC |