CVE-2025-15039
Analyzed Analyzed - Analysis Complete

Authentication Bypass in Conditional Authentication Script

Vulnerability report for CVE-2025-15039, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-12

Assigner: WSO2 LLC

Description

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-12
Generated
2026-08-18
AI Q&A
2026-08-06
EPSS Evaluated
2026-08-17
NVD
EUVD

Affected Vendors & Products

Showing 37 associated CPEs
Vendor Product Version / Range
wso2 api_control_plane From 4.5.0 (inc) to 4.5.0.45 (exc)
wso2 api_control_plane From 4.6.0 (inc) to 4.6.0.9 (exc)
wso2 api_manager From 2.6.0 (inc) to 2.6.0.150 (exc)
wso2 api_manager From 3.0.0 (inc) to 3.0.0.180 (exc)
wso2 api_manager From 3.1.0 (inc) to 3.1.0.356 (exc)
wso2 api_manager From 3.2.0 (inc) to 3.2.0.460 (exc)
wso2 api_manager From 3.2.1 (inc) to 3.2.1.79 (exc)
wso2 api_manager From 4.0.0 (inc) to 4.0.0.381 (exc)
wso2 api_manager From 4.1.0 (inc) to 4.1.0.244 (exc)
wso2 api_manager From 4.2.0 (inc) to 4.2.0.184 (exc)
wso2 api_manager From 4.3.0 (inc) to 4.3.0.95 (exc)
wso2 api_manager From 4.4.0 (inc) to 4.4.0.59 (exc)
wso2 api_manager From 4.5.0 (inc) to 4.5.0.44 (exc)
wso2 api_manager From 4.6.0 (inc) to 4.6.0.8 (exc)
wso2 identity_server From 5.10.0 (inc) to 5.10.0.385 (exc)
wso2 identity_server From 5.11.0 (inc) to 5.11.0.432 (exc)
wso2 identity_server From 5.7.0 (inc) to 5.7.0.130 (exc)
wso2 identity_server From 5.8.0 (inc) to 5.8.0.133 (exc)
wso2 identity_server From 5.9.0 (inc) to 5.9.0.173 (exc)
wso2 identity_server From 6.0.0 (inc) to 6.0.0.259 (exc)
wso2 identity_server From 6.1.0 (inc) to 6.1.0.260 (exc)
wso2 identity_server From 7.0.0 (inc) to 7.0.0.138 (exc)
wso2 identity_server From 7.1.0 (inc) to 7.1.0.49 (exc)
wso2 identity_server From 7.2.0 (inc) to 7.2.0.7 (exc)
wso2 identity_server_as_key_manager From 5.10.0 (inc) to 5.10.0.376 (exc)
wso2 identity_server_as_key_manager From 5.7.0 (inc) to 5.7.0.129 (exc)
wso2 identity_server_as_key_manager From 5.9.0 (inc) to 5.9.0.179 (exc)
wso2 open_banking_am From 1.4.0 (inc) to 1.4.0.143 (exc)
wso2 open_banking_am From 1.5.0 (inc) to 1.5.0.144 (exc)
wso2 open_banking_am From 2.0.0 (inc) to 2.0.0.405 (exc)
wso2 open_banking_iam From 2.0.0 (inc) to 2.0.0.425 (exc)
wso2 traffic_manager From 4.5.0 (inc) to 4.5.0.43 (exc)
wso2 traffic_manager From 4.6.0 (inc) to 4.6.0.8 (exc)
wso2 universal_gateway From 4.5.0 (inc) to 4.5.0.44 (exc)
wso2 universal_gateway From 4.6.0 (inc) to 4.6.0.8 (exc)
wso2 open_banking_km From 1.4.0 (inc) to 1.4.0.137 (exc)
wso2 open_banking_km From 1.5.0 (inc) to 1.5.0.127 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the Conditional Authentication script used in WSO2 products. When a specific multi-step authentication pattern is configured with certain secondary authenticators, the script fails to enforce completion of all required authentication steps. This allows attackers to bypass intermediate authentication challenges by manipulating how the script handles callbacks and re-execution of steps.

Detection Guidance

Detection requires checking WSO2 product configurations for Conditional Authentication scripts with improper callback handling. Review authentication logs for incomplete multi-step flows where secondary authenticators (e.g., Passkey, Push Notifications) are bypassed. Verify if users with impacted authenticators have unauthorized access attempts.

Impact Analysis

If exploited, this vulnerability allows an attacker to gain unauthorized access to a targeted user account. The attacker only needs to complete initial authentication steps under specific conditions, bypassing full authentication. This could lead to account takeover, data breaches, or unauthorized actions within the affected system.

Compliance Impact

This vulnerability could lead to unauthorized access to user accounts, potentially exposing sensitive data. For GDPR, this may result in violations of data protection principles and unauthorized processing of personal data. Under HIPAA, it could compromise protected health information if exploited in healthcare systems using affected WSO2 products.

Mitigation Strategies

Apply public fixes from GitHub or update to the latest unaffected versions of WSO2 products. For WSO2 API Control Plane, update to versions beyond 4.6.0 or 4.5.0. For WSO2 API Manager, update to versions beyond 4.6.0. For WSO2 Identity Server, update to versions beyond 7.2.0.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15039. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart