CVE-2025-13166 Details
Description
The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically tied to this condition. The discovery of these usernames can facilitate subsequent brute force attacks, social engineering attempts, and information leakage, potentially leading to reputational damage, loss of customer trust, and regulatory non-compliance.
A vulnerability in WSO2 Identity Server versions 7.2.0 and 7.1.0 allows for username enumeration through the SMS OTP flow. The issue arises because the error messages during the OTP initiation process do not adequately obscure whether a mobile number is registered to an account. This flaw enables an attacker to infer the existence of user accounts, particularly targeting those without a configured mobile number. The enumeration of usernames could lead to brute force attacks, social engineering attempts, and information leakage, causing potential reputational damage and loss of customer trust.
WSO2 Identity Server users can apply the public fix available on GitHub. Support subscription holders should update to the specified update level or a higher version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4353/ | WSO2 LLC | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-203 | Observable Discrepancy | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| WSO2 Identity Server | 7.2.0 (semver) 7.1.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | WSO2 LLC |
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | WSO2 LLC |
Volerion