PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-13736 WSO2 CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:28.657Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects systems using Multi-Attribute Login, allowing attackers to discover valid usernames, which can increase the risk of brute force attacks, social engineering attacks, and targeted information leakage. Security teams and administrators should assess and mitigate this vulnerability, reviewing configurations, monitoring for potential attacks, and implementing additional authentication security measures. The vulnerability has a CVSS score of 3.7 and is considered Low-priority.

Vendor
WSO2
Product
WSO2 Identity Server as Key Manager
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Security teams and administrators responsible for systems using Multi-Attribute Login should assess and mitigate this vulnerability. They should review configurations, monitor for potential brute force attacks, and implement additional authentication security measures. This vulnerability may impact operators, platforms, and security teams, particularly those with affected systems or components.

Technical summary

CVE-2025-13736 is a vulnerability in Multi-Attribute Login that fails to consistently mask user account existence. When enabled, valid users' canonical usernames are displayed, while non-existent users' input is echoed. This may facilitate brute force attacks and social engineering. The vulnerability has a CVSS score of 3.7 and is considered Low-priority. Security teams should assess and mitigate this vulnerability, focusing on affected systems and configurations.

Defensive priority

Low-priority defensive review recommended due to limited information available.

Recommended defensive actions

  • Verify affected systems and configurations
  • Monitor for potential brute force attacks
  • Implement additional authentication security measures
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Plan vendor-supported updates or mitigations through normal change control

Evidence notes

The evidence for CVE-2025-13736 is limited. Official CVE and NVD records indicate a vulnerability exists in Multi-Attribute Login, but details are sparse. Defenders should verify affected systems, review configurations, and monitor for potential brute force attacks. Further verification is needed to understand the full scope of the vulnerability, including known and unknown affected systems, and to assess the potential impact on their specific environments.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-13736 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-13736

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-13736 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13736

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4013/

    ed10eef1-636d-4fbe-9993-6890dfa878f8

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.