CVE-2025-15039
Last modified
CVE-2025-15039 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WSO2 | WSO2 Identity Server | < 5.7.0; >= 5.7.0, < 5.7.0.130; >= 5.8.0, < 5.8.0.113; >= 5.9.0, < 5.9.0.173; >= 5.10.0, < 5.10.0.385; >= 5.11.0, < 5.11.0.432; >= 6.0.0, < 6.0.0.259; >= 6.1.0, < 6.1.0.260; >= 7.0.0, < 7.0.0.138; >= 7.1.0, < 7.1.0.45; >= 7.1.0, < 7.1.0.49; >= 7.2.0, < 7.2.0.7 |
| WSO2 | WSO2 API Manager | < 2.6.0; >= 2.6.0, < 2.6.0.150; >= 3.0.0, < 3.0.0.180; >= 3.1.0, < 3.1.0.356; >= 3.2.0, < 3.2.0.460; >= 3.2.1, < 3.2.1.79; >= 4.0.0, < 4.0.0.381; >= 4.1.0, < 4.1.0.244; >= 4.2.0, < 4.2.0.184; >= 4.3.0, < 4.3.0.95; >= 4.4.0, < 4.4.0.59; >= 4.5.0, < 4.5.0.44; >= 4.6.0, < 4.6.0.8 |
| WSO2 | WSO2 Open Banking AM | < 1.4.0; >= 1.4.0, < 1.4.0.143; >= 1.5.0, < 1.5.0.144; >= 2.0.0, < 2.0.0.405 |
| WSO2 | WSO2 Open Banking IAM | < 2.0.0; >= 2.0.0, < 2.0.0.425 |
| WSO2 | WSO2 Traffic Manager | < 4.5.0; >= 4.5.0, < 4.5.0.43; >= 4.6.0, < 4.6.0.8 |
| WSO2 | WSO2 Universal Gateway | >= 4.5.0, < 4.5.0.43; >= 4.5.0, < 4.5.0.44; >= 4.6.0, < 4.6.0.8 |
| WSO2 | WSO2 API Control Plane | >= 4.5.0, < 4.5.0.45; >= 4.6.0, < 4.6.0.9 |
| WSO2 | WSO2 Identity Server as Key Manager | < 5.7.0; >= 5.7.0, < 5.7.0.129; >= 5.9.0, < 5.9.0.179; >= 5.10.0, < 5.10.0.376 |
| WSO2 | WSO2 Open Banking KM | < 1.4.0; >= 1.4.0, < 1.4.0.137; >= 1.5.0, < 1.5.0.127 |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | >= 5.12.153, < 5.12.153.66; >= 5.12.387, < 5.12.387.48; >= 5.14.97, < 5.14.97.94; >= 5.17.5, < 5.17.5.337; >= 5.17.118, < 5.17.118.24; >= 5.18.187, < 5.18.187.334; >= 5.18.248, < 5.18.248.34; >= 5.23.8, < 5.23.8.221; >= 5.24.8, < 5.24.8.29; >= 5.25.92, < 5.25.92.177; >= 5.25.705, < 5.25.705.23; >= 5.25.713, < 5.25.713.12; >= 5.25.724, < 5.25.724.8; >= 5.25.736, < 5.25.736.3; >= 7.0.78, < 7.0.78.171; >= 7.8.23, < 7.8.23.95; >= 7.8.586, < 7.8.586.21 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2025-15039?
How severe is CVE-2025-15039?
How do I fix CVE-2025-15039?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-15033A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logge…6.5
- CVE-2025-15034A security flaw has been discovered in itsourcecode Student …9.8
- CVE-2025-15035Improper Input Validation vulnerability in TP-Link Archer AX…7.3
- CVE-2025-15036A path traversal vulnerability exists in the `extract_archiv…10
- CVE-2025-15037An Incorrect Permission Assignment vulnerability exists in t…6.8
- CVE-2025-15038An Out-of-Bounds Read vulnerability exists in the ASUS Busin…6.9
- CVE-2025-1504The Post Lockdown plugin for WordPress is vulnerable to Info…6.5
- CVE-2025-15041The BackWPup – WordPress Backup & Restore Plugin plugin for …7.2
- CVE-2025-15043The The Events Calendar plugin for WordPress is vulnerable t…5.4
- CVE-2025-15044A vulnerability was detected in Tenda WH450 1.0.0.18. Impact…9.8
- CVE-2025-15045A flaw has been found in Tenda WH450 1.0.0.18. The affected …9.8
- CVE-2025-15046A vulnerability has been found in Tenda WH450 1.0.0.18. The …9.8
Are you affected by CVE-2025-15039?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
