An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.
CERTVDE·CWE-204·Published 2025-06-24