← Back to CVE List
CVE-2025-15039NVD
Vulnerability Summary
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.
Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
CVSS v3.1 Base Metrics — Score 9.4 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityLow
Affected & Patched Versions
- Wso2 Api Control Plane >= 4.5.0 and < 4.5.0.45
- Wso2 Api Control Plane >= 4.6.0 and < 4.6.0.9
- Wso2 Api Manager >= 2.6.0 and < 2.6.0.150
- Wso2 Api Manager >= 3.0.0 and < 3.0.0.180
- Wso2 Api Manager >= 3.1.0 and < 3.1.0.356
- Wso2 Api Manager >= 3.2.0 and < 3.2.0.460
- Wso2 Api Manager >= 3.2.1 and < 3.2.1.79
- Wso2 Api Manager >= 4.0.0 and < 4.0.0.381
- Wso2 Api Manager >= 4.1.0 and < 4.1.0.244
- Wso2 Api Manager >= 4.2.0 and < 4.2.0.184
- Wso2 Api Manager >= 4.3.0 and < 4.3.0.95
- Wso2 Api Manager >= 4.4.0 and < 4.4.0.59
- Wso2 Api Manager >= 4.5.0 and < 4.5.0.44
- Wso2 Api Manager >= 4.6.0 and < 4.6.0.8
- Wso2 Identity Server >= 5.7.0 and < 5.7.0.130
- Wso2 Identity Server >= 5.8.0 and < 5.8.0.133
- Wso2 Identity Server >= 5.9.0 and < 5.9.0.173
- Wso2 Identity Server >= 5.10.0 and < 5.10.0.385
- Wso2 Identity Server >= 5.11.0 and < 5.11.0.432
- Wso2 Identity Server >= 6.0.0 and < 6.0.0.259
- Wso2 Identity Server >= 6.1.0 and < 6.1.0.260
- Wso2 Identity Server >= 7.0.0 and < 7.0.0.138
- Wso2 Identity Server >= 7.1.0 and < 7.1.0.49
- Wso2 Identity Server >= 7.2.0 and < 7.2.0.7
- Wso2 Identity Server As Key Manager >= 5.7.0 and < 5.7.0.129
- Wso2 Identity Server As Key Manager >= 5.9.0 and < 5.9.0.179
- Wso2 Identity Server As Key Manager >= 5.10.0 and < 5.10.0.376
- Wso2 Open Banking Am >= 1.4.0 and < 1.4.0.143
- Wso2 Open Banking Am >= 1.5.0 and < 1.5.0.144
- Wso2 Open Banking Am >= 2.0.0 and < 2.0.0.405
- Wso2 Open Banking Iam >= 2.0.0 and < 2.0.0.425
- Wso2 Open Banking Km >= 1.4.0 and < 1.4.0.137
- Wso2 Open Banking Km >= 1.5.0 and < 1.5.0.127
- Wso2 Traffic Manager >= 4.5.0 and < 4.5.0.43
- Wso2 Traffic Manager >= 4.6.0 and < 4.6.0.8
- Wso2 Universal Gateway >= 4.5.0 and < 4.5.0.44
- Wso2 Universal Gateway >= 4.6.0 and < 4.6.0.8
- Wso2 Api Control Plane 4.5.0.45
- Wso2 Api Control Plane 4.6.0.9
- Wso2 Api Manager 2.6.0.150
- Wso2 Api Manager 3.0.0.180
- Wso2 Api Manager 3.1.0.356
- Wso2 Api Manager 3.2.0.460
- Wso2 Api Manager 3.2.1.79
- Wso2 Api Manager 4.0.0.381
- Wso2 Api Manager 4.1.0.244
- Wso2 Api Manager 4.2.0.184
- Wso2 Api Manager 4.3.0.95
- Wso2 Api Manager 4.4.0.59
- Wso2 Api Manager 4.5.0.44
- Wso2 Api Manager 4.6.0.8
- Wso2 Identity Server 5.7.0.130
- Wso2 Identity Server 5.8.0.133
- Wso2 Identity Server 5.9.0.173
- Wso2 Identity Server 5.10.0.385
- Wso2 Identity Server 5.11.0.432
- Wso2 Identity Server 6.0.0.259
- Wso2 Identity Server 6.1.0.260
- Wso2 Identity Server 7.0.0.138
- Wso2 Identity Server 7.1.0.49
- Wso2 Identity Server 7.2.0.7
- Wso2 Identity Server As Key Manager 5.7.0.129
- Wso2 Identity Server As Key Manager 5.9.0.179
- Wso2 Identity Server As Key Manager 5.10.0.376
- Wso2 Open Banking Am 1.4.0.143
- Wso2 Open Banking Am 1.5.0.144
- Wso2 Open Banking Am 2.0.0.405
- Wso2 Open Banking Iam 2.0.0.425
- Wso2 Open Banking Km 1.4.0.137
- Wso2 Open Banking Km 1.5.0.127
- Wso2 Traffic Manager 4.5.0.43
- Wso2 Traffic Manager 4.6.0.8
- Wso2 Universal Gateway 4.5.0.44
- Wso2 Universal Gateway 4.6.0.8