Record summary

CVE-2025-15039 has a selected CVSS score of 9.4 (critical).

Description

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

10
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.5.0 to < 4.5.0.45affected
4.6.0 to < 4.6.0.9affected

Default status: unaffected

CVE ListBefore 2.6.0unknown
2.6.0 to < 2.6.0.150affected
3.0.0 to < 3.0.0.180affected
3.1.0 to < 3.1.0.356affected
3.2.0 to < 3.2.0.460affected
3.2.1 to < 3.2.1.79affected
4.0.0 to < 4.0.0.381affected
4.1.0 to < 4.1.0.244affected
4.2.0 to < 4.2.0.184affected
4.3.0 to < 4.3.0.95affected
4.4.0 to < 4.4.0.59affected
4.5.0 to < 4.5.0.44affected
Showing 12 of 13 version ranges

WSO2 Carbon Identity Application Authentication Framework

Browse WSO2 / WSO2 Carbon Identity Application Authentication Frameworkorg.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.framework

Default status: unknown

CVE List5.12.153 to < 5.12.153.66affected
5.12.387 to < 5.12.387.48affected
5.14.97 to < 5.14.97.94affected
5.17.5 to < 5.17.5.337affected
5.17.118 to < 5.17.118.24affected
5.18.187 to < 5.18.187.334affected
5.18.248 to < 5.18.248.34affected
5.23.8 to < 5.23.8.221affected
5.24.8 to < 5.24.8.29affected
5.25.92 to < 5.25.92.177affected
5.25.705 to < 5.25.705.23affected
5.25.713 to < 5.25.713.12affected
Showing 12 of 19 version ranges

Default status: unaffected

CVE ListBefore 5.7.0unknown
5.7.0 to < 5.7.0.130affected
5.8.0 to < 5.8.0.113affected
5.9.0 to < 5.9.0.173affected
5.10.0 to < 5.10.0.385affected
5.11.0 to < 5.11.0.432affected
6.0.0 to < 6.0.0.259affected
6.1.0 to < 6.1.0.260affected
7.0.0 to < 7.0.0.138affected
7.1.0 to < 7.1.0.45affected
7.1.0 to < 7.1.0.49affected
7.2.0 to < 7.2.0.7affected

WSO2 Identity Server as Key Manager

Browse WSO2 / WSO2 Identity Server as Key Manager

Default status: unaffected

CVE ListBefore 5.7.0unknown
5.7.0 to < 5.7.0.129affected
5.9.0 to < 5.9.0.179affected
5.10.0 to < 5.10.0.376affected

Default status: unaffected

CVE ListBefore 1.4.0unknown
1.4.0 to < 1.4.0.143affected
1.5.0 to < 1.5.0.144affected
2.0.0 to < 2.0.0.405affected

Default status: unaffected

CVE ListBefore 2.0.0unknown
2.0.0 to < 2.0.0.425affected

Default status: unaffected

CVE ListBefore 1.4.0unknown
1.4.0 to < 1.4.0.137affected
1.5.0 to < 1.5.0.127affected

Default status: unaffected

CVE ListBefore 4.5.0unknown
4.5.0 to < 4.5.0.43affected
4.6.0 to < 4.6.0.8affected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.43affected
4.5.0 to < 4.5.0.44affected
4.6.0 to < 4.6.0.8affected

References

2