CVE-2024-0391Disclosure(wso2 / identity_server)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-force and social engineering attacks. Attackers can leverage this information to craft targeted phishing campaigns or other malicious activities aimed at tricking users into divulging sensitive data, potentially damaging the organization's reputation and leading to regulatory non-compliance and financial consequences.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-204

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_server
  • identity_server_as_key_manager
  • open_banking_iam

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
identity_serveridentity_server_as_key_manageropen_banking_iam

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-11: 2Technical Details · 2026-05-11: 205-11
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2024-0391 The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accoun… https://www.cve.org/CVERecord?id=CVE-2024-0391

    Post summary

    The entry announces CVE‑2024‑0391, providing technical details on a user enumeration flaw in an email OTP flow, but offers no PoC, exploit, or mitigation information.

    00000156
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2024-0391 User Account Enumeration via Email OTP Flow Input Validation Failure https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-0391

    Post summary

    The entry references CVE-2024-0391, briefly describing an input‑validation weakness that could lead to user enumeration, but lacks any PoC, exploit code, patch, or active exploitation details.

    0000071
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2identity_server---
Appwso2identity_server_as_key_manager---
Appwso2open_banking_iam---

Explore more