CVE-2025-15039
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Summary
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.
Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WSO2 | WSO2 Identity Server | 0 < 5.7.0 | unknown |
| WSO2 | WSO2 Identity Server | 5.7.0 < 5.7.0.130 | affected |
| WSO2 | WSO2 Identity Server | 5.8.0 < 5.8.0.113 | affected |
| WSO2 | WSO2 Identity Server | 5.9.0 < 5.9.0.173 | affected |
| WSO2 | WSO2 Identity Server | 5.10.0 < 5.10.0.385 | affected |
| WSO2 | WSO2 Identity Server | 5.11.0 < 5.11.0.432 | affected |
| WSO2 | WSO2 Identity Server | 6.0.0 < 6.0.0.259 | affected |
| WSO2 | WSO2 Identity Server | 6.1.0 < 6.1.0.260 | affected |
| WSO2 | WSO2 Identity Server | 7.0.0 < 7.0.0.138 | affected |
| WSO2 | WSO2 Identity Server | 7.1.0 < 7.1.0.45 | affected |
| WSO2 | WSO2 Identity Server | 7.1.0 < 7.1.0.49 | affected |
| WSO2 | WSO2 Identity Server | 7.2.0 < 7.2.0.7 | affected |
| WSO2 | WSO2 API Manager | 0 < 2.6.0 | unknown |
| WSO2 | WSO2 API Manager | 2.6.0 < 2.6.0.150 | affected |
| WSO2 | WSO2 API Manager | 3.0.0 < 3.0.0.180 | affected |
| WSO2 | WSO2 API Manager | 3.1.0 < 3.1.0.356 | affected |
| WSO2 | WSO2 API Manager | 3.2.0 < 3.2.0.460 | affected |
| WSO2 | WSO2 API Manager | 3.2.1 < 3.2.1.79 | affected |
| WSO2 | WSO2 API Manager | 4.0.0 < 4.0.0.381 | affected |
| WSO2 | WSO2 API Manager | 4.1.0 < 4.1.0.244 | affected |
| WSO2 | WSO2 API Manager | 4.2.0 < 4.2.0.184 | affected |
| WSO2 | WSO2 API Manager | 4.3.0 < 4.3.0.95 | affected |
| WSO2 | WSO2 API Manager | 4.4.0 < 4.4.0.59 | affected |
| WSO2 | WSO2 API Manager | 4.5.0 < 4.5.0.44 | affected |
| WSO2 | WSO2 API Manager | 4.6.0 < 4.6.0.8 | affected |
| WSO2 | WSO2 Open Banking AM | 0 < 1.4.0 | unknown |
| WSO2 | WSO2 Open Banking AM | 1.4.0 < 1.4.0.143 | affected |
| WSO2 | WSO2 Open Banking AM | 1.5.0 < 1.5.0.144 | affected |
| WSO2 | WSO2 Open Banking AM | 2.0.0 < 2.0.0.405 | affected |
| WSO2 | WSO2 Open Banking IAM | 0 < 2.0.0 | unknown |
| WSO2 | WSO2 Open Banking IAM | 2.0.0 < 2.0.0.425 | affected |
| WSO2 | WSO2 Traffic Manager | 0 < 4.5.0 | unknown |
| WSO2 | WSO2 Traffic Manager | 4.5.0 < 4.5.0.43 | affected |
| WSO2 | WSO2 Traffic Manager | 4.6.0 < 4.6.0.8 | affected |
| WSO2 | WSO2 Universal Gateway | 4.5.0 < 4.5.0.43 | affected |
| WSO2 | WSO2 Universal Gateway | 4.5.0 < 4.5.0.44 | affected |
| WSO2 | WSO2 Universal Gateway | 4.6.0 < 4.6.0.8 | affected |
| WSO2 | WSO2 API Control Plane | 4.5.0 < 4.5.0.45 | affected |
| WSO2 | WSO2 API Control Plane | 4.6.0 < 4.6.0.9 | affected |
| WSO2 | WSO2 Identity Server as Key Manager | 0 < 5.7.0 | unknown |
| WSO2 | WSO2 Identity Server as Key Manager | 5.7.0 < 5.7.0.129 | affected |
| WSO2 | WSO2 Identity Server as Key Manager | 5.9.0 < 5.9.0.179 | affected |
| WSO2 | WSO2 Identity Server as Key Manager | 5.10.0 < 5.10.0.376 | affected |
| WSO2 | WSO2 Open Banking KM | 0 < 1.4.0 | unknown |
| WSO2 | WSO2 Open Banking KM | 1.4.0 < 1.4.0.137 | affected |
| WSO2 | WSO2 Open Banking KM | 1.5.0 < 1.5.0.127 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.12.153 < 5.12.153.66 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.12.387 < 5.12.387.48 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.14.97 < 5.14.97.94 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.17.5 < 5.17.5.337 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.17.118 < 5.17.118.24 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.18.187 < 5.18.187.334 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.18.248 < 5.18.248.34 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.23.8 < 5.23.8.221 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.24.8 < 5.24.8.29 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.25.92 < 5.25.92.177 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.25.705 < 5.25.705.23 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.25.713 < 5.25.713.12 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.25.724 < 5.25.724.8 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.25.736 < 5.25.736.3 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 7.0.78 < 7.0.78.171 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 7.8.23 < 7.8.23.95 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 7.8.586 < 7.8.586.21 | affected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.25.738 <= 5.25.* | unaffected |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 7.8.646 <= * | unaffected |
Weaknesses
- CWE-693: CWE-693: Protection Mechanism Failure
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.