← Back

CVE-2025-15039

nvd nist
Published: Aug 6, 2026Modified: Aug 12, 2026

JSON object

Loading...
9.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Exploitability: 3.9 / Impact: 5.5
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Affected (37)

9 products
Api Control Plane
Api Manager
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Open Banking Km
Traffic Manager
Universal Gateway
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.45
From 4.6.0 to 4.6.0.9
Wso2
From 2.6.0 to 2.6.0.150
From 3.0.0 to 3.0.0.180
From 3.1.0 to 3.1.0.356
From 3.2.0 to 3.2.0.460
From 3.2.1 to 3.2.1.79
From 4.0.0 to 4.0.0.381
From 4.1.0 to 4.1.0.244
From 4.2.0 to 4.2.0.184
From 4.3.0 to 4.3.0.95
From 4.4.0 to 4.4.0.59
From 4.5.0 to 4.5.0.44
From 4.6.0 to 4.6.0.8
Wso2
From 5.10.0 to 5.10.0.385
From 5.11.0 to 5.11.0.432
From 5.7.0 to 5.7.0.130
From 5.8.0 to 5.8.0.133
From 5.9.0 to 5.9.0.173
From 6.0.0 to 6.0.0.259
From 6.1.0 to 6.1.0.260
From 7.0.0 to 7.0.0.138
From 7.1.0 to 7.1.0.49
From 7.2.0 to 7.2.0.7
Wso2
From 5.10.0 to 5.10.0.376
From 5.7.0 to 5.7.0.129
From 5.9.0 to 5.9.0.179
Wso2
From 1.4.0 to 1.4.0.143
From 1.5.0 to 1.5.0.144
From 2.0.0 to 2.0.0.405
From 2.0.0 to 2.0.0.425
Wso2
From 1.4.0 to 1.4.0.137
From 1.5.0 to 1.5.0.127
Wso2
From 4.5.0 to 4.5.0.43
From 4.6.0 to 4.6.0.8
Wso2
From 4.5.0 to 4.5.0.44
From 4.6.0 to 4.6.0.8

References (1)

Timeline

No history available yet.