CVE-2025-15039
Last modified
CVE-2025-15039 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Control Plane | >= 4.5.0, < 4.5.0.45 |
| Wso2 | Api Control Plane | >= 4.6.0, < 4.6.0.9 |
| Wso2 | Api Manager | >= 2.6.0, < 2.6.0.150 |
| Wso2 | Api Manager | >= 3.0.0, < 3.0.0.180 |
| Wso2 | Api Manager | >= 3.1.0, < 3.1.0.356 |
| Wso2 | Api Manager | >= 3.2.0, < 3.2.0.460 |
| Wso2 | Api Manager | >= 3.2.1, < 3.2.1.79 |
| Wso2 | Api Manager | >= 4.0.0, < 4.0.0.381 |
| Wso2 | Api Manager | >= 4.1.0, < 4.1.0.244 |
| Wso2 | Api Manager | >= 4.2.0, < 4.2.0.184 |
| Wso2 | Api Manager | >= 4.3.0, < 4.3.0.95 |
| Wso2 | Api Manager | >= 4.4.0, < 4.4.0.59 |
| Wso2 | Api Manager | >= 4.5.0, < 4.5.0.44 |
| Wso2 | Api Manager | >= 4.6.0, < 4.6.0.8 |
| Wso2 | Identity Server | >= 5.7.0, < 5.7.0.130 |
| Wso2 | Identity Server | >= 5.8.0, < 5.8.0.133 |
| Wso2 | Identity Server | >= 5.9.0, < 5.9.0.173 |
| Wso2 | Identity Server | >= 5.10.0, < 5.10.0.385 |
| Wso2 | Identity Server | >= 5.11.0, < 5.11.0.432 |
| Wso2 | Identity Server | >= 6.0.0, < 6.0.0.259 |
| Wso2 | Identity Server | >= 6.1.0, < 6.1.0.260 |
| Wso2 | Identity Server | >= 7.0.0, < 7.0.0.138 |
| Wso2 | Identity Server | >= 7.1.0, < 7.1.0.49 |
| Wso2 | Identity Server | >= 7.2.0, < 7.2.0.7 |
| Wso2 | Identity Server As Key Manager | >= 5.7.0, < 5.7.0.129 |
| Wso2 | Identity Server As Key Manager | >= 5.9.0, < 5.9.0.179 |
| Wso2 | Identity Server As Key Manager | >= 5.10.0, < 5.10.0.376 |
| Wso2 | Open Banking Am | >= 1.4.0, < 1.4.0.143 |
| Wso2 | Open Banking Am | >= 1.5.0, < 1.5.0.144 |
| Wso2 | Open Banking Am | >= 2.0.0, < 2.0.0.405 |
| Wso2 | Open Banking Iam | >= 2.0.0, < 2.0.0.425 |
| Wso2 | Open Banking Km | >= 1.4.0, < 1.4.0.137 |
| Wso2 | Open Banking Km | >= 1.5.0, < 1.5.0.127 |
| Wso2 | Traffic Manager | >= 4.5.0, < 4.5.0.43 |
| Wso2 | Traffic Manager | >= 4.6.0, < 4.6.0.8 |
| Wso2 | Universal Gateway | >= 4.5.0, < 4.5.0.44 |
| Wso2 | Universal Gateway | >= 4.6.0, < 4.6.0.8 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-15039?
How severe is CVE-2025-15039?
How do I fix CVE-2025-15039?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-15033A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logge…6.5
- CVE-2025-15034A security flaw has been discovered in itsourcecode Student …9.8
- CVE-2025-15035Improper Input Validation vulnerability in TP-Link Archer AX…7.3
- CVE-2025-15036A path traversal vulnerability exists in the `extract_archiv…10
- CVE-2025-15037An Incorrect Permission Assignment vulnerability exists in t…6.8
- CVE-2025-15038An Out-of-Bounds Read vulnerability exists in the ASUS Busin…6.9
- CVE-2025-1504The Post Lockdown plugin for WordPress is vulnerable to Info…6.5
- CVE-2025-15041The BackWPup – WordPress Backup & Restore Plugin plugin for …7.2
- CVE-2025-15043The The Events Calendar plugin for WordPress is vulnerable t…5.4
- CVE-2025-15044A vulnerability was detected in Tenda WH450 1.0.0.18. Impact…9.8
- CVE-2025-15045A flaw has been found in Tenda WH450 1.0.0.18. The affected …9.8
- CVE-2025-15046A vulnerability has been found in Tenda WH450 1.0.0.18. The …9.8
Are you affected by CVE-2025-15039?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
