CVE-2025-15039
Received Received - Intake

Authentication Bypass in Conditional Authentication Script

Vulnerability report for CVE-2025-15039, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WSO2 LLC

Description

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
wso2 api_control_plane 4.6.0
wso2 api_control_plane 4.5.0
wso2 api_manager From 2.6.0 (inc) to 4.6.0 (inc)
wso2 identity_server From 5.7.0 (inc) to 7.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the Conditional Authentication script used in WSO2 products. When a specific multi-step authentication pattern is configured with certain secondary authenticators, the script fails to enforce completion of all required authentication steps. This allows attackers to bypass intermediate authentication challenges by manipulating how the script handles callbacks and re-execution of steps.

Impact Analysis

If exploited, this vulnerability allows an attacker to gain unauthorized access to a targeted user account. The attacker only needs to complete initial authentication steps under specific conditions, bypassing full authentication. This could lead to account takeover, data breaches, or unauthorized actions within the affected system.

Mitigation Strategies

Apply public fixes from GitHub or update to the latest unaffected versions of WSO2 products. For WSO2 API Control Plane, update to versions beyond 4.6.0 or 4.5.0. For WSO2 API Manager, update to versions beyond 4.6.0. For WSO2 Identity Server, update to versions beyond 7.2.0.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15039. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart