CWE-204— Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.— MITRE CWE catalog
198 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-204page 1 of 4
- CVE-2018-25350CRITICALCVSS 9.8EG 9.82026-05-26
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze…
- CVE-2026-15747CRITICALCVSS 9.1EG 9.12026-07-14
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, …
- CVE-2026-69519HIGHCVSS 8.6EG 8.62026-08-20
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
- CVE-2025-5485HIGHCVSS 8.6EG 8.62025-06-12
User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from …
- CVE-2026-19205HIGHCVSS 7.5EG 7.52026-09-04
Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.
- CVE-2026-19080HIGHCVSS 7.5EG 7.52026-09-04
Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.
- CVE-2026-27462HIGHCVSS 7.5EG 7.52026-08-21
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has…
- CVE-2026-33419HIGHCVSS 7.5EG 7.52026-03-24
MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined we…
- CVE-2025-12455HIGHCVSS 7.5EG 7.52026-03-13
Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. The vulnerability could lead to Password Brute Forcing in Vertica management console application.This issue affects Vertica: from 10.0 …
- CVE-2025-46390HIGHCVSS 7.5EG 7.52025-08-06
CWE-204: Observable Response Discrepancy
- CVE-2025-3092HIGHCVSS 7.5EG 7.52025-06-24
An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
- CVE-2021-20049HIGHCVSS 7.5EG 7.52021-12-23
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x…
- CVE-2021-34580HIGHCVSS 7.5EG 7.52021-10-27
In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
- CVE-2019-25338HIGHCVSS 5.3EG 7.52026-02-12
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and disti…
- CVE-2022-22520HIGHCVSS 5.3EG 7.52022-09-14
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
- CVE-2026-60007HIGHCVSS 7.4EG 7.42026-08-04
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa…
- CVE-2026-4113HIGHCVSS 7.2EG 7.22026-04-09
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
- CVE-2026-66002MEDIUMCVSS 6.9EG 6.92026-08-20
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request…
- CVE-2026-54739MEDIUMCVSS 6.9EG 6.92026-08-19
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in crates/api/api/src/local_user/login.rs returns different errors depending on whether the username_or_email value exists. L…
- CVE-2026-54768MEDIUMCVSS 6.9EG 6.92026-07-31
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordRes…
- CVE-2026-54445MEDIUMCVSS 6.9EG 6.92026-06-05
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers …
- CVE-2021-47717MEDIUMCVSS 6.9EG 6.92025-12-09
IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumerate valid users by exploiting the 'ctl00$MainContent$UserName' POST parameter. Attackers can send requests with valid us…
- CVE-2025-34155MEDIUMCVSS 6.9EG 6.92025-10-23
Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username exists or not, allowing an unauthenticated remote…
- CVE-2025-2910MEDIUMCVSS 6.9EG 6.92025-03-28
User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.
- CVE-2025-23214MEDIUMCVSS 6.9EG 6.92025-01-20
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. By monitoring the error code returned in the login, it is possible to figure out whether a user exist…
- CVE-2026-86758MEDIUMCVSS 6.5EG 6.52026-09-09
Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all licen…
- CVE-2026-34264MEDIUMCVSS 6.5EG 6.52026-04-14
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized …
- CVE-2025-67874MEDIUMCVSS 6.5EG 6.52025-12-16
ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of …
- CVE-2025-61907MEDIUMCVSS 6.5EG 6.52025-10-16
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. Th…
- CVE-2025-61789MEDIUMCVSS 6.5EG 6.52025-10-16
Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hi…
- CVE-2023-46170MEDIUMCVSS 6.5EG 6.52024-03-07
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily read files after enumerating file names.
- CVE-2022-39315MEDIUMCVSS 6.5EG 6.52022-10-25
Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the config. It can only …
- CVE-2021-38476MEDIUMCVSS 6.5EG 6.52021-10-19
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and validates the existence of a username. This may allow an attacker to enumerate different user accounts.
- CVE-2025-56764MEDIUMCVSS 5.3EG 6.52025-09-29
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.
- CVE-2026-43926MEDIUMCVSS 6.3EG 6.32026-06-04
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-API controller and is not covered by FOSSB…
- CVE-2024-28232MEDIUMCVSS 6.2EG 6.22024-04-01
Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in …
- CVE-2024-24766MEDIUMCVSS 6.2EG 6.22024-03-06
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enume…
- CVE-2025-9824MEDIUMCVSS 5.9EG 5.92025-09-03
ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has…
- CVE-2024-40627MEDIUMCVSS 5.8EG 5.82024-07-15
Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by `OpaMiddleware`, even when they lack authentication, and are passed through directly to the application. `OpaMiddleware…
- CVE-2026-107843MEDIUMCVSS 5.3EG 5.32026-10-09
Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the …
- CVE-2026-82043MEDIUMCVSS 5.3EG 5.32026-10-02
UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoi…
- CVE-2026-104439MEDIUMCVSS 5.3EG 5.32026-10-02
YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePasse…
- CVE-2026-86778MEDIUMCVSS 5.3EG 5.32026-09-30
Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
- CVE-2026-84717MEDIUMCVSS 5.3EG 5.32026-09-23
A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target t…
- CVE-2026-89173MEDIUMCVSS 5.3EG 5.32026-09-11
Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.
- CVE-2026-9161MEDIUMCVSS 5.3EG 5.32026-09-10
Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respo…
- CVE-2026-81033MEDIUMCVSS 5.3EG 5.32026-08-26
Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a not-fou…
- CVE-2026-75575MEDIUMCVSS 5.3EG 5.32026-08-25
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAnon/…
- CVE-2026-14672MEDIUMCVSS 5.3EG 5.32026-08-13
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iteration…
- CVE-2026-73306MEDIUMCVSS 5.3EG 5.32026-08-12
Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/…
Map vulnerabilities like CWE-204 to your infrastructure
EchelonGraph correlates every CVE — across CWE-204 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →