CVE-2025-15039
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
Record summary
CVE-2025-15039 has a selected CVSS score of 9.4 (critical).
Description
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
10| Product | Source | Version range | Status |
|---|---|---|---|
WSO2 API Control PlaneBrowse WSO2 / WSO2 API Control PlaneDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.45 | affected |
| 4.6.0 to < 4.6.0.9 | affected | ||
WSO2 API ManagerBrowse WSO2 / WSO2 API ManagerDefault status: unaffected | CVE List | Before 2.6.0 | unknown |
| 2.6.0 to < 2.6.0.150 | affected | ||
| 3.0.0 to < 3.0.0.180 | affected | ||
| 3.1.0 to < 3.1.0.356 | affected | ||
| 3.2.0 to < 3.2.0.460 | affected | ||
| 3.2.1 to < 3.2.1.79 | affected | ||
| 4.0.0 to < 4.0.0.381 | affected | ||
| 4.1.0 to < 4.1.0.244 | affected | ||
| 4.2.0 to < 4.2.0.184 | affected | ||
| 4.3.0 to < 4.3.0.95 | affected | ||
| 4.4.0 to < 4.4.0.59 | affected | ||
| 4.5.0 to < 4.5.0.44 | affected | ||
| Showing 12 of 13 version ranges | |||
WSO2 Carbon Identity Application Authentication FrameworkBrowse WSO2 / WSO2 Carbon Identity Application Authentication Frameworkorg.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.authentication.frameworkDefault status: unknown | CVE List | 5.12.153 to < 5.12.153.66 | affected |
| 5.12.387 to < 5.12.387.48 | affected | ||
| 5.14.97 to < 5.14.97.94 | affected | ||
| 5.17.5 to < 5.17.5.337 | affected | ||
| 5.17.118 to < 5.17.118.24 | affected | ||
| 5.18.187 to < 5.18.187.334 | affected | ||
| 5.18.248 to < 5.18.248.34 | affected | ||
| 5.23.8 to < 5.23.8.221 | affected | ||
| 5.24.8 to < 5.24.8.29 | affected | ||
| 5.25.92 to < 5.25.92.177 | affected | ||
| 5.25.705 to < 5.25.705.23 | affected | ||
| 5.25.713 to < 5.25.713.12 | affected | ||
| Showing 12 of 19 version ranges | |||
WSO2 Identity ServerBrowse WSO2 / WSO2 Identity ServerDefault status: unaffected | CVE List | Before 5.7.0 | unknown |
| 5.7.0 to < 5.7.0.130 | affected | ||
| 5.8.0 to < 5.8.0.113 | affected | ||
| 5.9.0 to < 5.9.0.173 | affected | ||
| 5.10.0 to < 5.10.0.385 | affected | ||
| 5.11.0 to < 5.11.0.432 | affected | ||
| 6.0.0 to < 6.0.0.259 | affected | ||
| 6.1.0 to < 6.1.0.260 | affected | ||
| 7.0.0 to < 7.0.0.138 | affected | ||
| 7.1.0 to < 7.1.0.45 | affected | ||
| 7.1.0 to < 7.1.0.49 | affected | ||
| 7.2.0 to < 7.2.0.7 | affected | ||
WSO2 Identity Server as Key ManagerBrowse WSO2 / WSO2 Identity Server as Key ManagerDefault status: unaffected | CVE List | Before 5.7.0 | unknown |
| 5.7.0 to < 5.7.0.129 | affected | ||
| 5.9.0 to < 5.9.0.179 | affected | ||
| 5.10.0 to < 5.10.0.376 | affected | ||
WSO2 Open Banking AMBrowse WSO2 / WSO2 Open Banking AMDefault status: unaffected | CVE List | Before 1.4.0 | unknown |
| 1.4.0 to < 1.4.0.143 | affected | ||
| 1.5.0 to < 1.5.0.144 | affected | ||
| 2.0.0 to < 2.0.0.405 | affected | ||
WSO2 Open Banking IAMBrowse WSO2 / WSO2 Open Banking IAMDefault status: unaffected | CVE List | Before 2.0.0 | unknown |
| 2.0.0 to < 2.0.0.425 | affected | ||
WSO2 Open Banking KMBrowse WSO2 / WSO2 Open Banking KMDefault status: unaffected | CVE List | Before 1.4.0 | unknown |
| 1.4.0 to < 1.4.0.137 | affected | ||
| 1.5.0 to < 1.5.0.127 | affected | ||
WSO2 Traffic ManagerBrowse WSO2 / WSO2 Traffic ManagerDefault status: unaffected | CVE List | Before 4.5.0 | unknown |
| 4.5.0 to < 4.5.0.43 | affected | ||
| 4.6.0 to < 4.6.0.8 | affected | ||
WSO2 Universal GatewayBrowse WSO2 / WSO2 Universal GatewayDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.43 | affected |
| 4.5.0 to < 4.5.0.44 | affected | ||
| 4.6.0 to < 4.6.0.8 | affected | ||