CVE-2025-15039 PUBLISHED

Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products

Assigner: WSO2
Reserved: 23.12.2025 Published: 06.08.2026 Updated: 06.08.2026

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.

Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CVSS Score: 9.4

Product Status

Vendor WSO2
Product WSO2 Identity Server
Versions Default: unaffected
  • unknown from 0 to 5.7.0 (excl.)
  • affected from 5.7.0 to 5.7.0.130 (excl.)
  • affected from 5.8.0 to 5.8.0.113 (excl.)
  • affected from 5.9.0 to 5.9.0.173 (excl.)
  • affected from 5.10.0 to 5.10.0.385 (excl.)
  • affected from 5.11.0 to 5.11.0.432 (excl.)
  • affected from 6.0.0 to 6.0.0.259 (excl.)
  • affected from 6.1.0 to 6.1.0.260 (excl.)
  • affected from 7.0.0 to 7.0.0.138 (excl.)
  • affected from 7.1.0 to 7.1.0.45 (excl.)
  • affected from 7.1.0 to 7.1.0.49 (excl.)
  • affected from 7.2.0 to 7.2.0.7 (excl.)
Vendor WSO2
Product WSO2 API Manager
Versions Default: unaffected
  • unknown from 0 to 2.6.0 (excl.)
  • affected from 2.6.0 to 2.6.0.150 (excl.)
  • affected from 3.0.0 to 3.0.0.180 (excl.)
  • affected from 3.1.0 to 3.1.0.356 (excl.)
  • affected from 3.2.0 to 3.2.0.460 (excl.)
  • affected from 3.2.1 to 3.2.1.79 (excl.)
  • affected from 4.0.0 to 4.0.0.381 (excl.)
  • affected from 4.1.0 to 4.1.0.244 (excl.)
  • affected from 4.2.0 to 4.2.0.184 (excl.)
  • affected from 4.3.0 to 4.3.0.95 (excl.)
  • affected from 4.4.0 to 4.4.0.59 (excl.)
  • affected from 4.5.0 to 4.5.0.44 (excl.)
  • affected from 4.6.0 to 4.6.0.8 (excl.)
Vendor WSO2
Product WSO2 Open Banking AM
Versions Default: unaffected
  • unknown from 0 to 1.4.0 (excl.)
  • affected from 1.4.0 to 1.4.0.143 (excl.)
  • affected from 1.5.0 to 1.5.0.144 (excl.)
  • affected from 2.0.0 to 2.0.0.405 (excl.)
Vendor WSO2
Product WSO2 Open Banking IAM
Versions Default: unaffected
  • unknown from 0 to 2.0.0 (excl.)
  • affected from 2.0.0 to 2.0.0.425 (excl.)
Vendor WSO2
Product WSO2 Traffic Manager
Versions Default: unaffected
  • unknown from 0 to 4.5.0 (excl.)
  • affected from 4.5.0 to 4.5.0.43 (excl.)
  • affected from 4.6.0 to 4.6.0.8 (excl.)
Vendor WSO2
Product WSO2 Universal Gateway
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.43 (excl.)
  • affected from 4.5.0 to 4.5.0.44 (excl.)
  • affected from 4.6.0 to 4.6.0.8 (excl.)
Vendor WSO2
Product WSO2 API Control Plane
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.45 (excl.)
  • affected from 4.6.0 to 4.6.0.9 (excl.)
Vendor WSO2
Product WSO2 Identity Server as Key Manager
Versions Default: unaffected
  • unknown from 0 to 5.7.0 (excl.)
  • affected from 5.7.0 to 5.7.0.129 (excl.)
  • affected from 5.9.0 to 5.9.0.179 (excl.)
  • affected from 5.10.0 to 5.10.0.376 (excl.)
Vendor WSO2
Product WSO2 Open Banking KM
Versions Default: unaffected
  • unknown from 0 to 1.4.0 (excl.)
  • affected from 1.4.0 to 1.4.0.137 (excl.)
  • affected from 1.5.0 to 1.5.0.127 (excl.)
Vendor WSO2
Product WSO2 Carbon Identity Application Authentication Framework
Versions Default: unknown
  • affected from 5.12.153 to 5.12.153.66 (excl.)
  • affected from 5.12.387 to 5.12.387.48 (excl.)
  • affected from 5.14.97 to 5.14.97.94 (excl.)
  • affected from 5.17.5 to 5.17.5.337 (excl.)
  • affected from 5.17.118 to 5.17.118.24 (excl.)
  • affected from 5.18.187 to 5.18.187.334 (excl.)
  • affected from 5.18.248 to 5.18.248.34 (excl.)
  • affected from 5.23.8 to 5.23.8.221 (excl.)
  • affected from 5.24.8 to 5.24.8.29 (excl.)
  • affected from 5.25.92 to 5.25.92.177 (excl.)
  • affected from 5.25.705 to 5.25.705.23 (excl.)
  • affected from 5.25.713 to 5.25.713.12 (excl.)
  • affected from 5.25.724 to 5.25.724.8 (excl.)
  • affected from 5.25.736 to 5.25.736.3 (excl.)
  • affected from 7.0.78 to 7.0.78.171 (excl.)
  • affected from 7.8.23 to 7.8.23.95 (excl.)
  • affected from 7.8.586 to 7.8.586.21 (excl.)
  • unaffected from 5.25.738 to 5.25.* (incl.)
  • unaffected from 7.8.646 to * (incl.)

Solutions

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/#solution

References

Problem Types

  • CWE-693: Protection Mechanism Failure CWE

Impacts

  • CAPEC-134 CAPEC-134: Circumventing Security Controls