← All CVEs

CVE-2025-15039

critical · 9.4

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

9.4
CVSS
0.4%
EPSS (exploit prob.)
34th
EPSS percentile
2026-08-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Weaknesses

CWE-693

Affected products

VendorProductAffected versions
wso2api_control_plane>= 4.5.0, < 4.5.0.45
wso2api_control_plane>= 4.6.0, < 4.6.0.9
wso2api_manager>= 2.6.0, < 2.6.0.150
wso2api_manager>= 3.0.0, < 3.0.0.180
wso2api_manager>= 3.1.0, < 3.1.0.356
wso2api_manager>= 3.2.0, < 3.2.0.460
wso2api_manager>= 3.2.1, < 3.2.1.79
wso2api_manager>= 4.0.0, < 4.0.0.381
wso2api_manager>= 4.1.0, < 4.1.0.244
wso2api_manager>= 4.2.0, < 4.2.0.184
wso2api_manager>= 4.3.0, < 4.3.0.95
wso2api_manager>= 4.4.0, < 4.4.0.59
wso2api_manager>= 4.5.0, < 4.5.0.44
wso2api_manager>= 4.6.0, < 4.6.0.8
wso2identity_server>= 5.7.0, < 5.7.0.130
wso2identity_server>= 5.8.0, < 5.8.0.133
wso2identity_server>= 5.9.0, < 5.9.0.173
wso2identity_server>= 5.10.0, < 5.10.0.385
wso2identity_server>= 5.11.0, < 5.11.0.432
wso2identity_server>= 6.0.0, < 6.0.0.259
wso2identity_server>= 6.1.0, < 6.1.0.260
wso2identity_server>= 7.0.0, < 7.0.0.138
wso2identity_server>= 7.1.0, < 7.1.0.49
wso2identity_server>= 7.2.0, < 7.2.0.7
wso2identity_server_as_key_manager>= 5.7.0, < 5.7.0.129
wso2identity_server_as_key_manager>= 5.9.0, < 5.9.0.179
wso2identity_server_as_key_manager>= 5.10.0, < 5.10.0.376
wso2open_banking_am>= 1.4.0, < 1.4.0.143
wso2open_banking_am>= 1.5.0, < 1.5.0.144
wso2open_banking_am>= 2.0.0, < 2.0.0.405
wso2open_banking_iam>= 2.0.0, < 2.0.0.425
wso2open_banking_km>= 1.4.0, < 1.4.0.137
wso2open_banking_km>= 1.5.0, < 1.5.0.127
wso2traffic_manager>= 4.5.0, < 4.5.0.43
wso2traffic_manager>= 4.6.0, < 4.6.0.8
wso2universal_gateway>= 4.5.0, < 4.5.0.44
wso2universal_gateway>= 4.6.0, < 4.6.0.8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-15039