CVE-2025-15039

CRITICALCVSS 9.4/10EPSS 0.39%

Last modified

CVE-2025-15039 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. EPSS estimates a 0.39% chance of exploitation in the next 30 days.

Description

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Metrics

CVSS 3.1
9.4/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS Probability
0.39%

31.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
WSO2WSO2 Identity Server< 5.7.0; >= 5.7.0, < 5.7.0.130; >= 5.8.0, < 5.8.0.113; >= 5.9.0, < 5.9.0.173; >= 5.10.0, < 5.10.0.385; >= 5.11.0, < 5.11.0.432; >= 6.0.0, < 6.0.0.259; >= 6.1.0, < 6.1.0.260; >= 7.0.0, < 7.0.0.138; >= 7.1.0, < 7.1.0.45; >= 7.1.0, < 7.1.0.49; >= 7.2.0, < 7.2.0.7
WSO2WSO2 API Manager< 2.6.0; >= 2.6.0, < 2.6.0.150; >= 3.0.0, < 3.0.0.180; >= 3.1.0, < 3.1.0.356; >= 3.2.0, < 3.2.0.460; >= 3.2.1, < 3.2.1.79; >= 4.0.0, < 4.0.0.381; >= 4.1.0, < 4.1.0.244; >= 4.2.0, < 4.2.0.184; >= 4.3.0, < 4.3.0.95; >= 4.4.0, < 4.4.0.59; >= 4.5.0, < 4.5.0.44; >= 4.6.0, < 4.6.0.8
WSO2WSO2 Open Banking AM< 1.4.0; >= 1.4.0, < 1.4.0.143; >= 1.5.0, < 1.5.0.144; >= 2.0.0, < 2.0.0.405
WSO2WSO2 Open Banking IAM< 2.0.0; >= 2.0.0, < 2.0.0.425
WSO2WSO2 Traffic Manager< 4.5.0; >= 4.5.0, < 4.5.0.43; >= 4.6.0, < 4.6.0.8
WSO2WSO2 Universal Gateway>= 4.5.0, < 4.5.0.43; >= 4.5.0, < 4.5.0.44; >= 4.6.0, < 4.6.0.8
WSO2WSO2 API Control Plane>= 4.5.0, < 4.5.0.45; >= 4.6.0, < 4.6.0.9
WSO2WSO2 Identity Server as Key Manager< 5.7.0; >= 5.7.0, < 5.7.0.129; >= 5.9.0, < 5.9.0.179; >= 5.10.0, < 5.10.0.376
WSO2WSO2 Open Banking KM< 1.4.0; >= 1.4.0, < 1.4.0.137; >= 1.5.0, < 1.5.0.127
WSO2WSO2 Carbon Identity Application Authentication Framework>= 5.12.153, < 5.12.153.66; >= 5.12.387, < 5.12.387.48; >= 5.14.97, < 5.14.97.94; >= 5.17.5, < 5.17.5.337; >= 5.17.118, < 5.17.118.24; >= 5.18.187, < 5.18.187.334; >= 5.18.248, < 5.18.248.34; >= 5.23.8, < 5.23.8.221; >= 5.24.8, < 5.24.8.29; >= 5.25.92, < 5.25.92.177; >= 5.25.705, < 5.25.705.23; >= 5.25.713, < 5.25.713.12; >= 5.25.724, < 5.25.724.8; >= 5.25.736, < 5.25.736.3; >= 7.0.78, < 7.0.78.171; >= 7.8.23, < 7.8.23.95; >= 7.8.586, < 7.8.586.21

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2025-15039?
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
How severe is CVE-2025-15039?
CVE-2025-15039 has a CVSS score of 9.4/10 (CRITICAL severity). The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2025-15039?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-15039?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST