CWE-204— Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.— MITRE CWE catalog
181 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-204page 4 of 4
- CVE-2026-33323MEDIUMCVSS 5.3EG 5.32026-03-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return d…
- CVE-2026-33419HIGHCVSS 7.5EG 7.52026-03-24
MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined we…
- CVE-2026-33688MEDIUMCVSS 5.3EG 5.32026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allow…
- CVE-2026-34264MEDIUMCVSS 6.5EG 6.52026-04-14
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized …
- CVE-2026-34319MEDIUMCVSS 5.0EG 5.02026-04-21
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker…
- CVE-2026-39851MEDIUMCVSS 4.3EG 4.32026-04-08
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed…
- CVE-2026-4045LOWCVSS 3.7EG 3.72026-03-12
A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable response discrepancy. The attack can be ex…
- CVE-2026-40485MEDIUMCVSS 5.3EG 5.32026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on whether a username exists: 404 for non-existent u…
- CVE-2026-4113HIGHCVSS 7.2EG 7.22026-04-09
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
- CVE-2026-42218MEDIUMCVSS 5.3EG 5.32026-07-20
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on …
- CVE-2026-43926MEDIUMCVSS 6.3EG 6.32026-06-04
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-API controller and is not covered by FOSSB…
- CVE-2026-44306MEDIUMCVSS 5.3EG 5.32026-05-12
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an account existed for a given email address. An unauthenticated attacker could …
- CVE-2026-44753LOWCVSS 3.7EG 3.72026-07-14
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation …
- CVE-2026-45294MEDIUMCVSS 5.3EG 5.32026-05-29
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing us…
- CVE-2026-45620MEDIUMCVSS 5.3EG 5.32026-05-18
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables…
- CVE-2026-47083MEDIUMCVSS 4.3EG 4.32026-07-16
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Se…
- CVE-2026-53422MEDIUMCVSS 4.3EG 4.32026-07-02
Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler i…
- CVE-2026-53908MEDIUMCVSS 4.3EG 4.32026-07-01
MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for valid and invalid users during username reminder and password reset operations. An attacker can lev…
- CVE-2026-53947MEDIUMCVSS 5.3EG 5.32026-06-24
Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a r…
- CVE-2026-54445MEDIUMCVSS 6.9EG 6.92026-06-05
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers …
- CVE-2026-54739MEDIUMCVSS 6.9EG 6.92026-08-19
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in crates/api/api/src/local_user/login.rs returns different errors depending on whether the username_or_email value exists. L…
- CVE-2026-54768MEDIUMCVSS 6.9EG 6.92026-07-31
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordRes…
- CVE-2026-55998MEDIUMCVSS 5.3EG 5.32026-08-05
The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemte…
- CVE-2026-60007HIGHCVSS 7.4EG 7.42026-08-04
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa…
- CVE-2026-61503MEDIUMCVSS 5.3EG 5.32026-07-13
Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the…
- CVE-2026-66002MEDIUMCVSS 6.9EG 6.92026-08-20
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request…
- CVE-2026-69519HIGHCVSS 8.6EG 8.62026-08-20
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
- CVE-2026-72588MEDIUMCVSS 5.3EG 5.32026-08-10
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 …
- CVE-2026-73306MEDIUMCVSS 5.3EG 5.32026-08-12
Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/…
- CVE-2026-75575MEDIUMCVSS 5.3EG 5.32026-08-25
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAnon/…
- CVE-2026-8242LOWCVSS 3.7EG 3.72026-05-10
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. The…
Map vulnerabilities like CWE-204 to your infrastructure
EchelonGraph correlates every CVE — across CWE-204 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →