CVE-2025-15039
critical · 9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| wso2 | api_control_plane | >= 4.5.0, < 4.5.0.45 |
| wso2 | api_control_plane | >= 4.6.0, < 4.6.0.9 |
| wso2 | api_manager | >= 2.6.0, < 2.6.0.150 |
| wso2 | api_manager | >= 3.0.0, < 3.0.0.180 |
| wso2 | api_manager | >= 3.1.0, < 3.1.0.356 |
| wso2 | api_manager | >= 3.2.0, < 3.2.0.460 |
| wso2 | api_manager | >= 3.2.1, < 3.2.1.79 |
| wso2 | api_manager | >= 4.0.0, < 4.0.0.381 |
| wso2 | api_manager | >= 4.1.0, < 4.1.0.244 |
| wso2 | api_manager | >= 4.2.0, < 4.2.0.184 |
| wso2 | api_manager | >= 4.3.0, < 4.3.0.95 |
| wso2 | api_manager | >= 4.4.0, < 4.4.0.59 |
| wso2 | api_manager | >= 4.5.0, < 4.5.0.44 |
| wso2 | api_manager | >= 4.6.0, < 4.6.0.8 |
| wso2 | identity_server | >= 5.7.0, < 5.7.0.130 |
| wso2 | identity_server | >= 5.8.0, < 5.8.0.133 |
| wso2 | identity_server | >= 5.9.0, < 5.9.0.173 |
| wso2 | identity_server | >= 5.10.0, < 5.10.0.385 |
| wso2 | identity_server | >= 5.11.0, < 5.11.0.432 |
| wso2 | identity_server | >= 6.0.0, < 6.0.0.259 |
| wso2 | identity_server | >= 6.1.0, < 6.1.0.260 |
| wso2 | identity_server | >= 7.0.0, < 7.0.0.138 |
| wso2 | identity_server | >= 7.1.0, < 7.1.0.49 |
| wso2 | identity_server | >= 7.2.0, < 7.2.0.7 |
| wso2 | identity_server_as_key_manager | >= 5.7.0, < 5.7.0.129 |
| wso2 | identity_server_as_key_manager | >= 5.9.0, < 5.9.0.179 |
| wso2 | identity_server_as_key_manager | >= 5.10.0, < 5.10.0.376 |
| wso2 | open_banking_am | >= 1.4.0, < 1.4.0.143 |
| wso2 | open_banking_am | >= 1.5.0, < 1.5.0.144 |
| wso2 | open_banking_am | >= 2.0.0, < 2.0.0.405 |
| wso2 | open_banking_iam | >= 2.0.0, < 2.0.0.425 |
| wso2 | open_banking_km | >= 1.4.0, < 1.4.0.137 |
| wso2 | open_banking_km | >= 1.5.0, < 1.5.0.127 |
| wso2 | traffic_manager | >= 4.5.0, < 4.5.0.43 |
| wso2 | traffic_manager | >= 4.6.0, < 4.6.0.8 |
| wso2 | universal_gateway | >= 4.5.0, < 4.5.0.44 |
| wso2 | universal_gateway | >= 4.6.0, < 4.6.0.8 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-15039