CVE-2025-15039
Analyzed
Analyzed - Analysis Complete
Authentication Bypass in Conditional Authentication Script
Vulnerability report for CVE-2025-15039, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-06
Last updated on: 2026-08-12
Assigner: WSO2 LLC
Description
Description
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.
Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wso2 | api_control_plane | From 4.5.0 (inc) to 4.5.0.45 (exc) |
| wso2 | api_control_plane | From 4.6.0 (inc) to 4.6.0.9 (exc) |
| wso2 | api_manager | From 2.6.0 (inc) to 2.6.0.150 (exc) |
| wso2 | api_manager | From 3.0.0 (inc) to 3.0.0.180 (exc) |
| wso2 | api_manager | From 3.1.0 (inc) to 3.1.0.356 (exc) |
| wso2 | api_manager | From 3.2.0 (inc) to 3.2.0.460 (exc) |
| wso2 | api_manager | From 3.2.1 (inc) to 3.2.1.79 (exc) |
| wso2 | api_manager | From 4.0.0 (inc) to 4.0.0.381 (exc) |
| wso2 | api_manager | From 4.1.0 (inc) to 4.1.0.244 (exc) |
| wso2 | api_manager | From 4.2.0 (inc) to 4.2.0.184 (exc) |
| wso2 | api_manager | From 4.3.0 (inc) to 4.3.0.95 (exc) |
| wso2 | api_manager | From 4.4.0 (inc) to 4.4.0.59 (exc) |
| wso2 | api_manager | From 4.5.0 (inc) to 4.5.0.44 (exc) |
| wso2 | api_manager | From 4.6.0 (inc) to 4.6.0.8 (exc) |
| wso2 | identity_server | From 5.10.0 (inc) to 5.10.0.385 (exc) |
| wso2 | identity_server | From 5.11.0 (inc) to 5.11.0.432 (exc) |
| wso2 | identity_server | From 5.7.0 (inc) to 5.7.0.130 (exc) |
| wso2 | identity_server | From 5.8.0 (inc) to 5.8.0.133 (exc) |
| wso2 | identity_server | From 5.9.0 (inc) to 5.9.0.173 (exc) |
| wso2 | identity_server | From 6.0.0 (inc) to 6.0.0.259 (exc) |
| wso2 | identity_server | From 6.1.0 (inc) to 6.1.0.260 (exc) |
| wso2 | identity_server | From 7.0.0 (inc) to 7.0.0.138 (exc) |
| wso2 | identity_server | From 7.1.0 (inc) to 7.1.0.49 (exc) |
| wso2 | identity_server | From 7.2.0 (inc) to 7.2.0.7 (exc) |
| wso2 | identity_server_as_key_manager | From 5.10.0 (inc) to 5.10.0.376 (exc) |
| wso2 | identity_server_as_key_manager | From 5.7.0 (inc) to 5.7.0.129 (exc) |
| wso2 | identity_server_as_key_manager | From 5.9.0 (inc) to 5.9.0.179 (exc) |
| wso2 | open_banking_am | From 1.4.0 (inc) to 1.4.0.143 (exc) |
| wso2 | open_banking_am | From 1.5.0 (inc) to 1.5.0.144 (exc) |
| wso2 | open_banking_am | From 2.0.0 (inc) to 2.0.0.405 (exc) |
| wso2 | open_banking_iam | From 2.0.0 (inc) to 2.0.0.425 (exc) |
| wso2 | traffic_manager | From 4.5.0 (inc) to 4.5.0.43 (exc) |
| wso2 | traffic_manager | From 4.6.0 (inc) to 4.6.0.8 (exc) |
| wso2 | universal_gateway | From 4.5.0 (inc) to 4.5.0.44 (exc) |
| wso2 | universal_gateway | From 4.6.0 (inc) to 4.6.0.8 (exc) |
| wso2 | open_banking_km | From 1.4.0 (inc) to 1.4.0.137 (exc) |
| wso2 | open_banking_km | From 1.5.0 (inc) to 1.5.0.127 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |