216.73.216.233

CVE-2026-25138

· Published 25/02/2026 20:23 · Modified 26/02/2026 17:23

Labels: CVE-2026-25138 2026-02-25CVE-2026-25138CWE-204[email protected]

Essential information

Published
25/02/2026 20:23
Modified
26/02/2026 17:23
Author
Creator
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Prior to versions 35.8.3, 38.5.4, and 39.3.1, the WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. Versions 35.8.3, 38.5.4, and 39.3.1 fix the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
rucio / rucio cpe:2.3:a:rucio:rucio:<35.8.3:*:*:*:*:*:*
rucio / rucio cpe:2.3:a:rucio:rucio:<38.5.4:*:*:*:*:*:*
rucio / rucio cpe:2.3:a:rucio:rucio:<39.3.1:*:*:*:*:*:*

References