Security Advisory

CVE-2025-56423Username enumeration via distinct login error messages

OpenAtlas · Austrian Academy of Sciences (ÖAW)

CVE published 24 Nov 2025 · discovered 19 May 2025

Overview

The OpenAtlas login form revealed whether a username existed by returning different error messages. This allowed valid accounts to be enumerated without knowing any passwords.

Technical findings

OpenAtlas responded differently to failed logins depending on whether the account existed, making it relatively easy to identify valid usernames.

This does not directly enable account takeover, but a verified username list removes uncertainty for attackers and improves their prospects for password spraying, credential stuffing and phishing.

The fix standardizes login responses so that error messages no longer reveal whether the username or password was incorrect.

Why it matters

An attacker can automatically try possible usernames and compare the responses. That does not compromise an account by itself, but it makes password spraying, credential stuffing and targeted phishing significantly easier.

Potential impact

  • Enables valid-username enumeration, facilitating brute-force attacks, credential stuffing and phishing.

Remediation

  • Upgrade to OpenAtlas 8.12.1 or later.
  • Return the same generic error message for all failed login attempts.
  • Normalize response times and HTTP behavior as well to prevent alternative enumeration signals.
  • Implement rate limiting and monitoring for repeated failed logins.

Affected and fixed versions

Affected<= 8.12.0
Fixed / vendor-confirmed8.12.1

Disclosure timeline

  1. Discovery

    Discovered during an on-premises penetration test.

  2. Initial contact

    Contacted the OpenAtlas team about the disclosure process.

  3. Delivery coordinated

    Agreed on a communication channel for the technical report.

  4. Report sent

    Submitted the complete report to the vendor.

  5. Fix confirmation

    The vendor confirmed the fix.

  6. CVE assignment

    Received the CVE ID during the disclosure process.

References

Related OpenAtlas research