CVE-2024-0391
The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-force and social engineering attacks. Attackers can leverage this information to craft targeted phishing campaigns or other malicious activities aimed at tricking users into divulging sensitive data, potentially damaging the organization's reputation and leading to regulatory non-compliance and financial consequences.
Published:May 11, 2026
Last Modified:May 27, 2026
EPS:May 11, 2026
EPSS Score:0.0003
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Wso2
Product
Email Otp Authenticator
Wso2
Email Otp Authenticator
Vendor
Wso2
Product
Identity Server
Wso2
Identity Server
Vendor
Wso2
Product
Identity Server As Key Manager
Wso2
Identity Server As Key Manager
Vendor
Wso2
Product
Open Banking Iam
Wso2
Open Banking Iam
Vendor
Wso2
Product
Wso2 Carbon Authenticator Library For Emailotp
Wso2
Wso2 Carbon Authenticator Library For Emailotp
Vendor
Wso2
Product
Wso2 Identity Server
Wso2
Wso2 Identity Server
Vendor
Wso2
Product
Wso2 Identity Server As Key Manager
Wso2
Wso2 Identity Server As Key Manager
Vendor
Wso2
Product
Wso2 Open Banking Iam
Wso2
Wso2 Open Banking Iam
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
