Critical
Low
Medium
CVE-2025-1396
Overview
A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the validate_username setting. This behavior allows malicious actors ...
Critical
Low
Medium
No items found.