Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
Summary
| CVE | CVE-2025-15039 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:29 UTC |
| Updated | 2026-08-12 19:32:37 UTC |
| Description | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps. |
Risk And Classification
Primary CVSS: v3.1 9.4 CRITICAL from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
EPSS: 0.003910000 probability, percentile 0.318760000 (date 2026-08-09)
Problem Types: CWE-693 | CWE-693 CWE-693: Protection Mechanism Failure
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 9.4 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
| 3.1 | CNA | CVSS | 9.4 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
LowCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wso2 | Api Control Plane | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 Identity Server | unknown 5.7.0 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.7.0 5.7.0.130 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.8.0 5.8.0.113 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.9.0 5.9.0.173 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.10.0 5.10.0.385 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 5.11.0 5.11.0.432 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 6.0.0 6.0.0.259 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 6.1.0 6.1.0.260 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.0.0 7.0.0.138 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.1.0 7.1.0.45 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.1.0 7.1.0.49 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server | affected 7.2.0 7.2.0.7 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | unknown 2.6.0 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 2.6.0 2.6.0.150 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.0.0 3.0.0.180 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.1.0 3.1.0.356 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.2.0 3.2.0.460 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 3.2.1 3.2.1.79 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.0.0 4.0.0.381 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.1.0 4.1.0.244 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.2.0 4.2.0.184 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.3.0 4.3.0.95 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.4.0 4.4.0.59 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.5.0 4.5.0.44 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.6.0 4.6.0.8 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking AM | unknown 1.4.0 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking AM | affected 1.4.0 1.4.0.143 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking AM | affected 1.5.0 1.5.0.144 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking AM | affected 2.0.0 2.0.0.405 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking IAM | unknown 2.0.0 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking IAM | affected 2.0.0 2.0.0.425 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | unknown 4.5.0 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.5.0 4.5.0.43 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.6.0 4.6.0.8 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.5.0 4.5.0.43 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.5.0 4.5.0.44 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.6.0 4.6.0.8 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.5.0 4.5.0.45 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.6.0 4.6.0.9 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | unknown 5.7.0 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | affected 5.7.0 5.7.0.129 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | affected 5.9.0 5.9.0.179 custom | Not specified |
| CNA | WSO2 | WSO2 Identity Server As Key Manager | affected 5.10.0 5.10.0.376 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking KM | unknown 1.4.0 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking KM | affected 1.4.0 1.4.0.137 custom | Not specified |
| CNA | WSO2 | WSO2 Open Banking KM | affected 1.5.0 1.5.0.127 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.12.153 5.12.153.66 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.12.387 5.12.387.48 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.14.97 5.14.97.94 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.17.5 5.17.5.337 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.17.118 5.17.118.24 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.18.187 5.18.187.334 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.18.248 5.18.248.34 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.23.8 5.23.8.221 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.24.8 5.24.8.29 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.25.92 5.25.92.177 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.25.705 5.25.705.23 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.25.713 5.25.713.12 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.25.724 5.25.724.8 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 5.25.736 5.25.736.3 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 7.0.78 7.0.78.171 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 7.8.23 7.8.23.95 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | affected 7.8.586 7.8.586.21 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | unaffected 5.25.738 5.25.* custom | Not specified |
| CNA | WSO2 | WSO2 Carbon Identity Application Authentication Framework | unaffected 7.8.646 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/#solution
There are currently no legacy QID mappings associated with this CVE.