CVE Watchtower

← Back to CVE List

CVE-2025-15039NVD

Vulnerability Summary

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.

Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Severity Level
CRITICAL(9.4)
Published Date
Aug 6, 2026
Last Modified
Sep 29, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.67%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics — Score 9.4 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityLow

Affected & Patched Versions

Affected Versions
  • Wso2 Api Control Plane >= 4.5.0 and < 4.5.0.45
  • Wso2 Api Control Plane >= 4.6.0 and < 4.6.0.9
  • Wso2 Api Manager >= 2.6.0 and < 2.6.0.150
  • Wso2 Api Manager >= 3.0.0 and < 3.0.0.180
  • Wso2 Api Manager >= 3.1.0 and < 3.1.0.356
  • Wso2 Api Manager >= 3.2.0 and < 3.2.0.460
  • Wso2 Api Manager >= 3.2.1 and < 3.2.1.79
  • Wso2 Api Manager >= 4.0.0 and < 4.0.0.381
  • Wso2 Api Manager >= 4.1.0 and < 4.1.0.244
  • Wso2 Api Manager >= 4.2.0 and < 4.2.0.184
  • Wso2 Api Manager >= 4.3.0 and < 4.3.0.95
  • Wso2 Api Manager >= 4.4.0 and < 4.4.0.59
  • Wso2 Api Manager >= 4.5.0 and < 4.5.0.44
  • Wso2 Api Manager >= 4.6.0 and < 4.6.0.8
  • Wso2 Identity Server >= 5.7.0 and < 5.7.0.130
  • Wso2 Identity Server >= 5.8.0 and < 5.8.0.133
  • Wso2 Identity Server >= 5.9.0 and < 5.9.0.173
  • Wso2 Identity Server >= 5.10.0 and < 5.10.0.385
  • Wso2 Identity Server >= 5.11.0 and < 5.11.0.432
  • Wso2 Identity Server >= 6.0.0 and < 6.0.0.259
  • Wso2 Identity Server >= 6.1.0 and < 6.1.0.260
  • Wso2 Identity Server >= 7.0.0 and < 7.0.0.138
  • Wso2 Identity Server >= 7.1.0 and < 7.1.0.49
  • Wso2 Identity Server >= 7.2.0 and < 7.2.0.7
  • Wso2 Identity Server As Key Manager >= 5.7.0 and < 5.7.0.129
  • Wso2 Identity Server As Key Manager >= 5.9.0 and < 5.9.0.179
  • Wso2 Identity Server As Key Manager >= 5.10.0 and < 5.10.0.376
  • Wso2 Open Banking Am >= 1.4.0 and < 1.4.0.143
  • Wso2 Open Banking Am >= 1.5.0 and < 1.5.0.144
  • Wso2 Open Banking Am >= 2.0.0 and < 2.0.0.405
  • Wso2 Open Banking Iam >= 2.0.0 and < 2.0.0.425
  • Wso2 Open Banking Km >= 1.4.0 and < 1.4.0.137
  • Wso2 Open Banking Km >= 1.5.0 and < 1.5.0.127
  • Wso2 Traffic Manager >= 4.5.0 and < 4.5.0.43
  • Wso2 Traffic Manager >= 4.6.0 and < 4.6.0.8
  • Wso2 Universal Gateway >= 4.5.0 and < 4.5.0.44
  • Wso2 Universal Gateway >= 4.6.0 and < 4.6.0.8
Patched Versions
  • Wso2 Api Control Plane 4.5.0.45
  • Wso2 Api Control Plane 4.6.0.9
  • Wso2 Api Manager 2.6.0.150
  • Wso2 Api Manager 3.0.0.180
  • Wso2 Api Manager 3.1.0.356
  • Wso2 Api Manager 3.2.0.460
  • Wso2 Api Manager 3.2.1.79
  • Wso2 Api Manager 4.0.0.381
  • Wso2 Api Manager 4.1.0.244
  • Wso2 Api Manager 4.2.0.184
  • Wso2 Api Manager 4.3.0.95
  • Wso2 Api Manager 4.4.0.59
  • Wso2 Api Manager 4.5.0.44
  • Wso2 Api Manager 4.6.0.8
  • Wso2 Identity Server 5.7.0.130
  • Wso2 Identity Server 5.8.0.133
  • Wso2 Identity Server 5.9.0.173
  • Wso2 Identity Server 5.10.0.385
  • Wso2 Identity Server 5.11.0.432
  • Wso2 Identity Server 6.0.0.259
  • Wso2 Identity Server 6.1.0.260
  • Wso2 Identity Server 7.0.0.138
  • Wso2 Identity Server 7.1.0.49
  • Wso2 Identity Server 7.2.0.7
  • Wso2 Identity Server As Key Manager 5.7.0.129
  • Wso2 Identity Server As Key Manager 5.9.0.179
  • Wso2 Identity Server As Key Manager 5.10.0.376
  • Wso2 Open Banking Am 1.4.0.143
  • Wso2 Open Banking Am 1.5.0.144
  • Wso2 Open Banking Am 2.0.0.405
  • Wso2 Open Banking Iam 2.0.0.425
  • Wso2 Open Banking Km 1.4.0.137
  • Wso2 Open Banking Km 1.5.0.127
  • Wso2 Traffic Manager 4.5.0.43
  • Wso2 Traffic Manager 4.6.0.8
  • Wso2 Universal Gateway 4.5.0.44
  • Wso2 Universal Gateway 4.6.0.8
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.