REDCap User Enumeration Vulnerability

Vulnerability

A user enumeration vulnerability exists in REDCap version 14.3.13. The issue arises because the application provides different error messages based on whether a username is valid or not. This discrepancy allows attackers to infer the existence of usernames by sending multiple HTTP authentication requests, effectively enabling brute-force attacks. Although there is a mechanism intended to protect against this type of attack, it inadvertently allows for user enumeration.

Impact

Exploitation of this vulnerability could lead to unauthorized knowledge of valid usernames, potentially facilitating further attacks such as password guessing or phishing.

Reproduction

To reproduce this vulnerability, send HTTP authentication requests to the REDCap application. Observe the response messages: valid usernames will generate a different error message compared to invalid ones. This difference can be used to systematically identify existing usernames.

Added: Jan 2, 2026, 3:34 PM
Updated: Jan 2, 2026, 5:13 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.6
exploitability
6.6
remediation
0.0
relevance
1.8
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.