CVE-2025-15039
EUVD-2025-21063206.08.2026, 08:16
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wso2 | api_control_plane | 4.5.0 ≤ 𝑥 < 4.5.0.45 |
| wso2 | api_control_plane | 4.6.0 ≤ 𝑥 < 4.6.0.9 |
| wso2 | api_manager | 2.6.0 ≤ 𝑥 < 2.6.0.150 |
| wso2 | api_manager | 3.0.0 ≤ 𝑥 < 3.0.0.180 |
| wso2 | api_manager | 3.1.0 ≤ 𝑥 < 3.1.0.356 |
| wso2 | api_manager | 3.2.0 ≤ 𝑥 < 3.2.0.460 |
| wso2 | api_manager | 3.2.1 ≤ 𝑥 < 3.2.1.79 |
| wso2 | api_manager | 4.0.0 ≤ 𝑥 < 4.0.0.381 |
| wso2 | api_manager | 4.1.0 ≤ 𝑥 < 4.1.0.244 |
| wso2 | api_manager | 4.2.0 ≤ 𝑥 < 4.2.0.184 |
| wso2 | api_manager | 4.3.0 ≤ 𝑥 < 4.3.0.95 |
| wso2 | api_manager | 4.4.0 ≤ 𝑥 < 4.4.0.59 |
| wso2 | api_manager | 4.5.0 ≤ 𝑥 < 4.5.0.44 |
| wso2 | api_manager | 4.6.0 ≤ 𝑥 < 4.6.0.8 |
| wso2 | identity_server | 5.7.0 ≤ 𝑥 < 5.7.0.130 |
| wso2 | identity_server | 5.8.0 ≤ 𝑥 < 5.8.0.133 |
| wso2 | identity_server | 5.9.0 ≤ 𝑥 < 5.9.0.173 |
| wso2 | identity_server | 5.10.0 ≤ 𝑥 < 5.10.0.385 |
| wso2 | identity_server | 5.11.0 ≤ 𝑥 < 5.11.0.432 |
| wso2 | identity_server | 6.0.0 ≤ 𝑥 < 6.0.0.259 |
| wso2 | identity_server | 6.1.0 ≤ 𝑥 < 6.1.0.260 |
| wso2 | identity_server | 7.0.0 ≤ 𝑥 < 7.0.0.138 |
| wso2 | identity_server | 7.1.0 ≤ 𝑥 < 7.1.0.49 |
| wso2 | identity_server | 7.2.0 ≤ 𝑥 < 7.2.0.7 |
| wso2 | identity_server_as_key_manager | 5.7.0 ≤ 𝑥 < 5.7.0.129 |
| wso2 | identity_server_as_key_manager | 5.9.0 ≤ 𝑥 < 5.9.0.179 |
| wso2 | identity_server_as_key_manager | 5.10.0 ≤ 𝑥 < 5.10.0.376 |
| wso2 | open_banking_am | 1.4.0 ≤ 𝑥 < 1.4.0.143 |
| wso2 | open_banking_am | 1.5.0 ≤ 𝑥 < 1.5.0.144 |
| wso2 | open_banking_am | 2.0.0 ≤ 𝑥 < 2.0.0.405 |
| wso2 | open_banking_iam | 2.0.0 ≤ 𝑥 < 2.0.0.425 |
| wso2 | open_banking_km | 1.4.0 ≤ 𝑥 < 1.4.0.137 |
| wso2 | open_banking_km | 1.5.0 ≤ 𝑥 < 1.5.0.127 |
| wso2 | traffic_manager | 4.5.0 ≤ 𝑥 < 4.5.0.43 |
| wso2 | traffic_manager | 4.6.0 ≤ 𝑥 < 4.6.0.8 |
| wso2 | universal_gateway | 4.5.0 ≤ 𝑥 < 4.5.0.44 |
| wso2 | universal_gateway | 4.6.0 ≤ 𝑥 < 4.6.0.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration