CVE-2025-15039

EUVD-2025-210632
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.

Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.4 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 34.48%
Affected Products (NVD)
VendorProductVersion
wso2api_control_plane
4.5.0 ≤
𝑥
< 4.5.0.45
wso2api_control_plane
4.6.0 ≤
𝑥
< 4.6.0.9
wso2api_manager
2.6.0 ≤
𝑥
< 2.6.0.150
wso2api_manager
3.0.0 ≤
𝑥
< 3.0.0.180
wso2api_manager
3.1.0 ≤
𝑥
< 3.1.0.356
wso2api_manager
3.2.0 ≤
𝑥
< 3.2.0.460
wso2api_manager
3.2.1 ≤
𝑥
< 3.2.1.79
wso2api_manager
4.0.0 ≤
𝑥
< 4.0.0.381
wso2api_manager
4.1.0 ≤
𝑥
< 4.1.0.244
wso2api_manager
4.2.0 ≤
𝑥
< 4.2.0.184
wso2api_manager
4.3.0 ≤
𝑥
< 4.3.0.95
wso2api_manager
4.4.0 ≤
𝑥
< 4.4.0.59
wso2api_manager
4.5.0 ≤
𝑥
< 4.5.0.44
wso2api_manager
4.6.0 ≤
𝑥
< 4.6.0.8
wso2identity_server
5.7.0 ≤
𝑥
< 5.7.0.130
wso2identity_server
5.8.0 ≤
𝑥
< 5.8.0.133
wso2identity_server
5.9.0 ≤
𝑥
< 5.9.0.173
wso2identity_server
5.10.0 ≤
𝑥
< 5.10.0.385
wso2identity_server
5.11.0 ≤
𝑥
< 5.11.0.432
wso2identity_server
6.0.0 ≤
𝑥
< 6.0.0.259
wso2identity_server
6.1.0 ≤
𝑥
< 6.1.0.260
wso2identity_server
7.0.0 ≤
𝑥
< 7.0.0.138
wso2identity_server
7.1.0 ≤
𝑥
< 7.1.0.49
wso2identity_server
7.2.0 ≤
𝑥
< 7.2.0.7
wso2identity_server_as_key_manager
5.7.0 ≤
𝑥
< 5.7.0.129
wso2identity_server_as_key_manager
5.9.0 ≤
𝑥
< 5.9.0.179
wso2identity_server_as_key_manager
5.10.0 ≤
𝑥
< 5.10.0.376
wso2open_banking_am
1.4.0 ≤
𝑥
< 1.4.0.143
wso2open_banking_am
1.5.0 ≤
𝑥
< 1.5.0.144
wso2open_banking_am
2.0.0 ≤
𝑥
< 2.0.0.405
wso2open_banking_iam
2.0.0 ≤
𝑥
< 2.0.0.425
wso2open_banking_km
1.4.0 ≤
𝑥
< 1.4.0.137
wso2open_banking_km
1.5.0 ≤
𝑥
< 1.5.0.127
wso2traffic_manager
4.5.0 ≤
𝑥
< 4.5.0.43
wso2traffic_manager
4.6.0 ≤
𝑥
< 4.6.0.8
wso2universal_gateway
4.5.0 ≤
𝑥
< 4.5.0.44
wso2universal_gateway
4.6.0 ≤
𝑥
< 4.6.0.8
𝑥
= Vulnerable software versions