CVE-2025-15039

Summary

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.

Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Affected Software

VendorProductVersion RangeStatus
WSO2WSO2 Identity Server0 < 5.7.0unknown
WSO2WSO2 Identity Server5.7.0 < 5.7.0.130affected
WSO2WSO2 Identity Server5.8.0 < 5.8.0.113affected
WSO2WSO2 Identity Server5.9.0 < 5.9.0.173affected
WSO2WSO2 Identity Server5.10.0 < 5.10.0.385affected
WSO2WSO2 Identity Server5.11.0 < 5.11.0.432affected
WSO2WSO2 Identity Server6.0.0 < 6.0.0.259affected
WSO2WSO2 Identity Server6.1.0 < 6.1.0.260affected
WSO2WSO2 Identity Server7.0.0 < 7.0.0.138affected
WSO2WSO2 Identity Server7.1.0 < 7.1.0.45affected
WSO2WSO2 Identity Server7.1.0 < 7.1.0.49affected
WSO2WSO2 Identity Server7.2.0 < 7.2.0.7affected
WSO2WSO2 API Manager0 < 2.6.0unknown
WSO2WSO2 API Manager2.6.0 < 2.6.0.150affected
WSO2WSO2 API Manager3.0.0 < 3.0.0.180affected
WSO2WSO2 API Manager3.1.0 < 3.1.0.356affected
WSO2WSO2 API Manager3.2.0 < 3.2.0.460affected
WSO2WSO2 API Manager3.2.1 < 3.2.1.79affected
WSO2WSO2 API Manager4.0.0 < 4.0.0.381affected
WSO2WSO2 API Manager4.1.0 < 4.1.0.244affected
WSO2WSO2 API Manager4.2.0 < 4.2.0.184affected
WSO2WSO2 API Manager4.3.0 < 4.3.0.95affected
WSO2WSO2 API Manager4.4.0 < 4.4.0.59affected
WSO2WSO2 API Manager4.5.0 < 4.5.0.44affected
WSO2WSO2 API Manager4.6.0 < 4.6.0.8affected
WSO2WSO2 Open Banking AM0 < 1.4.0unknown
WSO2WSO2 Open Banking AM1.4.0 < 1.4.0.143affected
WSO2WSO2 Open Banking AM1.5.0 < 1.5.0.144affected
WSO2WSO2 Open Banking AM2.0.0 < 2.0.0.405affected
WSO2WSO2 Open Banking IAM0 < 2.0.0unknown
WSO2WSO2 Open Banking IAM2.0.0 < 2.0.0.425affected
WSO2WSO2 Traffic Manager0 < 4.5.0unknown
WSO2WSO2 Traffic Manager4.5.0 < 4.5.0.43affected
WSO2WSO2 Traffic Manager4.6.0 < 4.6.0.8affected
WSO2WSO2 Universal Gateway4.5.0 < 4.5.0.43affected
WSO2WSO2 Universal Gateway4.5.0 < 4.5.0.44affected
WSO2WSO2 Universal Gateway4.6.0 < 4.6.0.8affected
WSO2WSO2 API Control Plane4.5.0 < 4.5.0.45affected
WSO2WSO2 API Control Plane4.6.0 < 4.6.0.9affected
WSO2WSO2 Identity Server as Key Manager0 < 5.7.0unknown
WSO2WSO2 Identity Server as Key Manager5.7.0 < 5.7.0.129affected
WSO2WSO2 Identity Server as Key Manager5.9.0 < 5.9.0.179affected
WSO2WSO2 Identity Server as Key Manager5.10.0 < 5.10.0.376affected
WSO2WSO2 Open Banking KM0 < 1.4.0unknown
WSO2WSO2 Open Banking KM1.4.0 < 1.4.0.137affected
WSO2WSO2 Open Banking KM1.5.0 < 1.5.0.127affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.12.153 < 5.12.153.66affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.12.387 < 5.12.387.48affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.14.97 < 5.14.97.94affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.17.5 < 5.17.5.337affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.17.118 < 5.17.118.24affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.18.187 < 5.18.187.334affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.18.248 < 5.18.248.34affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.23.8 < 5.23.8.221affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.24.8 < 5.24.8.29affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.25.92 < 5.25.92.177affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.25.705 < 5.25.705.23affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.25.713 < 5.25.713.12affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.25.724 < 5.25.724.8affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.25.736 < 5.25.736.3affected
WSO2WSO2 Carbon Identity Application Authentication Framework7.0.78 < 7.0.78.171affected
WSO2WSO2 Carbon Identity Application Authentication Framework7.8.23 < 7.8.23.95affected
WSO2WSO2 Carbon Identity Application Authentication Framework7.8.586 < 7.8.586.21affected
WSO2WSO2 Carbon Identity Application Authentication Framework5.25.738 <= 5.25.*unaffected
WSO2WSO2 Carbon Identity Application Authentication Framework7.8.646 <= *unaffected

Weaknesses

  • CWE-693: CWE-693: Protection Mechanism Failure

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References