AI description
CVE-2025-15039 describes a vulnerability found in the Conditional Authentication (Adaptive Authentication) script used across several WSO2 products, including API Control Plane, API Manager, Carbon Identity Application Authentication Framework, Identity Server, Identity Server as Key Manager, Open Banking AM, Open Banking IAM, Traffic Manager, and Universal Gateway. This flaw allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation of CVE-2025-15039 can lead to unauthorized access to a targeted user account. This vulnerability is exploitable under specific conditions: the application's login flow must include a particular secondary authenticator, the Conditional Authentication script needs to be configured with specific event callbacks and re-execute an authentication step, the targeted user must have one of the impacted authenticators enrolled, and the attacker must successfully complete any preceding authentication steps.
- Description
- The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
- Source
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- NVD status
- Analyzed
- Products
- api_control_plane, api_manager, identity_server, identity_server_as_key_manager, open_banking_am, open_banking_iam, open_banking_km, traffic_manager, universal_gateway
CVSS 3.1
- Type
- Secondary
- Base score
- 9.4
- Impact score
- 5.5
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
- Severity
- CRITICAL
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- CWE-693
- Hype score
- Not currently trending
CVE-2025-15039 WSO2 Identity Server Authentication bypass could enable account takeover in identity systems used for citizen services, open banking and enterprise access control Full analysis: https://t.co/Tv1IqHsfr8 #CyberSecurity #IdentitySecurity #VulnerabilityManagement
@TuringCyberObs
10 Aug 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2025-15039 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-s… https://t.co/bQTykUs8qX ----- Traducción: CVE-2025-15039 El … https://t.co/utmtNg
@infoflowcloud
6 Aug 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15039 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-s… https://t.co/n7lbLYlIiX
@CVEnew
6 Aug 2026
1803 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D995D5A2-BA46-4A37-A426-24FEBD31B347",
"versionEndExcluding": "4.5.0.45",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D67BE9A3-5C76-4852-8675-FFF32AD070AE",
"versionEndExcluding": "4.6.0.9",
"versionStartIncluding": "4.6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8A7BB442-F48D-4641-8B8C-62920136962A",
"versionEndExcluding": "2.6.0.150",
"versionStartIncluding": "2.6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7CC1A63A-04CC-4B33-B7D0-98F7A468ED20",
"versionEndExcluding": "3.0.0.180",
"versionStartIncluding": "3.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "779C4DD3-F4C1-4CAE-B7EE-F03A3131D594",
"versionEndExcluding": "3.1.0.356",
"versionStartIncluding": "3.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CED55268-DFD9-4A80-8D1A-094122AFC508",
"versionEndExcluding": "3.2.0.460",
"versionStartIncluding": "3.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F899F861-8F56-4167-8C77-5918A742C559",
"versionEndExcluding": "3.2.1.79",
"versionStartIncluding": "3.2.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "60C68B5F-2BD0-43A6-861F-577BD80F422F",
"versionEndExcluding": "4.0.0.381",
"versionStartIncluding": "4.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "06344918-D471-4245-B9FB-69825E99ABA0",
"versionEndExcluding": "4.1.0.244",
"versionStartIncluding": "4.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "905BF4EB-F2AD-4C98-B44B-05410C8C2C75",
"versionEndExcluding": "4.2.0.184",
"versionStartIncluding": "4.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "29179766-A9E7-4CFF-AF55-5300988D9483",
"versionEndExcluding": "4.3.0.95",
"versionStartIncluding": "4.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "04B57CE9-F224-416E-BB87-242AAA5AEE8B",
"versionEndExcluding": "4.4.0.59",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2E407764-1241-4A14-9EC7-2ABC224EF841",
"versionEndExcluding": "4.5.0.44",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B7E010B0-0929-40B7-8FC9-8E5B093AF2C7",
"versionEndExcluding": "4.6.0.8",
"versionStartIncluding": "4.6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5349A5C8-EA3F-4F3F-9A29-DC05D9B8BC00",
"versionEndExcluding": "5.7.0.130",
"versionStartIncluding": "5.7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "885643C6-A2D5-413C-93F2-13D5CED1FBB1",
"versionEndExcluding": "5.8.0.133",
"versionStartIncluding": "5.8.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4904520D-3B34-458A-B992-DB3F05C4BDA6",
"versionEndExcluding": "5.9.0.173",
"versionStartIncluding": "5.9.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5A789202-ADAA-4459-BBB4-0DF61B57E6A9",
"versionEndExcluding": "5.10.0.385",
"versionStartIncluding": "5.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B95E76-04B4-4625-B16B-3FD28632F9CC",
"versionEndExcluding": "5.11.0.432",
"versionStartIncluding": "5.11.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BAFCB3EB-6778-4B30-B289-F78327917AA5",
"versionEndExcluding": "6.0.0.259",
"versionStartIncluding": "6.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ACF5039C-DDBF-4026-9B9F-3EBDBEF5747E",
"versionEndExcluding": "6.1.0.260",
"versionStartIncluding": "6.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BB4EADE0-4780-463B-A2DF-D7BD23605D75",
"versionEndExcluding": "7.0.0.138",
"versionStartIncluding": "7.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "92A043AF-9648-471E-8B6C-B28D67FACE92",
"versionEndExcluding": "7.1.0.49",
"versionStartIncluding": "7.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "74774992-4FB3-482A-9F6C-DCED20B19B15",
"versionEndExcluding": "7.2.0.7",
"versionStartIncluding": "7.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "898D7438-A637-4E37-96F2-7F72342391EC",
"versionEndExcluding": "5.7.0.129",
"versionStartIncluding": "5.7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BE258A94-F8AC-43A9-A94D-1E397DA46417",
"versionEndExcluding": "5.9.0.179",
"versionStartIncluding": "5.9.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DF4C333C-084D-4F4A-A0DC-5F5E8BE6E530",
"versionEndExcluding": "5.10.0.376",
"versionStartIncluding": "5.10.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0E66821E-A871-461A-83F8-00B8C496846F",
"versionEndExcluding": "1.4.0.143",
"versionStartIncluding": "1.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B96B4DC1-A506-42B8-994C-B47EC30732A6",
"versionEndExcluding": "1.5.0.144",
"versionStartIncluding": "1.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0982A3BB-F361-4F00-BAB0-FCB30F7503C3",
"versionEndExcluding": "2.0.0.405",
"versionStartIncluding": "2.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_iam:*:*:*:*:*:*:*:*",
"matchCriteriaId": "613006EB-89F7-4D12-8C42-BA917BB32CE8",
"versionEndExcluding": "2.0.0.425",
"versionStartIncluding": "2.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_km:*:*:*:*:*:*:*:*",
"matchCriteriaId": "92B97896-B673-4240-85B3-0607E3EDF4C5",
"versionEndExcluding": "1.4.0.137",
"versionStartIncluding": "1.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:open_banking_km:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F242F2C4-8284-454D-8E46-96501EEB6A9A",
"versionEndExcluding": "1.5.0.127",
"versionStartIncluding": "1.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CF30B18A-4390-44B7-ADB7-A5C51D49E0A5",
"versionEndExcluding": "4.5.0.43",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "241CBE20-9DC0-4286-8F19-9472C700023F",
"versionEndExcluding": "4.6.0.8",
"versionStartIncluding": "4.6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C322AC69-86CB-4345-8493-84CA9754FADD",
"versionEndExcluding": "4.5.0.44",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A8268BF1-DC35-49E8-823F-0C4CCC351EA6",
"versionEndExcluding": "4.6.0.8",
"versionStartIncluding": "4.6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]