CVE-2025-15039

Published Aug 6, 2026

Last updated 3 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-15039 describes a vulnerability found in the Conditional Authentication (Adaptive Authentication) script used across several WSO2 products, including API Control Plane, API Manager, Carbon Identity Application Authentication Framework, Identity Server, Identity Server as Key Manager, Open Banking AM, Open Banking IAM, Traffic Manager, and Universal Gateway. This flaw allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation of CVE-2025-15039 can lead to unauthorized access to a targeted user account. This vulnerability is exploitable under specific conditions: the application's login flow must include a particular secondary authenticator, the Conditional Authentication script needs to be configured with specific event callbacks and re-execute an authentication step, the targeted user must have one of the impacted authenticators enrolled, and the attacker must successfully complete any preceding authentication steps.

Description
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.4
Impact score
5.5
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Severity
CRITICAL

Weaknesses

ed10eef1-636d-4fbe-9993-6890dfa878f8
CWE-693

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4