AI description
CVE-2025-15039 describes a vulnerability found in the Conditional Authentication (Adaptive Authentication) script used across several WSO2 products, including API Control Plane, API Manager, Carbon Identity Application Authentication Framework, Identity Server, Identity Server as Key Manager, Open Banking AM, Open Banking IAM, Traffic Manager, and Universal Gateway. This flaw allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation of CVE-2025-15039 can lead to unauthorized access to a targeted user account. This vulnerability is exploitable under specific conditions: the application's login flow must include a particular secondary authenticator, the Conditional Authentication script needs to be configured with specific event callbacks and re-execute an authentication step, the targeted user must have one of the impacted authenticators enrolled, and the attacker must successfully complete any preceding authentication steps.
- Description
- The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
- Source
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.4
- Impact score
- 5.5
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
- Severity
- CRITICAL
- ed10eef1-636d-4fbe-9993-6890dfa878f8
- CWE-693
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
🚨*CVE* CVE-2025-15039 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-s… https://t.co/bQTykUs8qX ----- Traducción: CVE-2025-15039 El … https://t.co/utmtNg
@infoflowcloud
6 Aug 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15039 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-s… https://t.co/n7lbLYlIiX
@CVEnew
6 Aug 2026
1803 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes