9.4

CVE-2025-15039

Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.

Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2Api Control Plane Version >= 4.5.0 < 4.5.0.45
Wso2Api Control Plane Version >= 4.6.0 < 4.6.0.9
Wso2Api Manager Version >= 2.6.0 < 2.6.0.150
Wso2Api Manager Version >= 3.0.0 < 3.0.0.180
Wso2Api Manager Version >= 3.1.0 < 3.1.0.356
Wso2Api Manager Version >= 3.2.0 < 3.2.0.460
Wso2Api Manager Version >= 3.2.1 < 3.2.1.79
Wso2Api Manager Version >= 4.0.0 < 4.0.0.381
Wso2Api Manager Version >= 4.1.0 < 4.1.0.244
Wso2Api Manager Version >= 4.2.0 < 4.2.0.184
Wso2Api Manager Version >= 4.3.0 < 4.3.0.95
Wso2Api Manager Version >= 4.4.0 < 4.4.0.59
Wso2Api Manager Version >= 4.5.0 < 4.5.0.44
Wso2Api Manager Version >= 4.6.0 < 4.6.0.8
Wso2Identity Server Version >= 5.7.0 < 5.7.0.130
Wso2Identity Server Version >= 5.8.0 < 5.8.0.133
Wso2Identity Server Version >= 5.9.0 < 5.9.0.173
Wso2Identity Server Version >= 5.10.0 < 5.10.0.385
Wso2Identity Server Version >= 5.11.0 < 5.11.0.432
Wso2Identity Server Version >= 6.0.0 < 6.0.0.259
Wso2Identity Server Version >= 6.1.0 < 6.1.0.260
Wso2Identity Server Version >= 7.0.0 < 7.0.0.138
Wso2Identity Server Version >= 7.1.0 < 7.1.0.49
Wso2Identity Server Version >= 7.2.0 < 7.2.0.7
Wso2Identity Server As Key Manager Version >= 5.7.0 < 5.7.0.129
Wso2Identity Server As Key Manager Version >= 5.9.0 < 5.9.0.179
Wso2Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.376
Wso2Open Banking Am Version >= 1.4.0 < 1.4.0.143
Wso2Open Banking Am Version >= 1.5.0 < 1.5.0.144
Wso2Open Banking Am Version >= 2.0.0 < 2.0.0.405
Wso2Open Banking Iam Version >= 2.0.0 < 2.0.0.425
Wso2Open Banking Km Version >= 1.4.0 < 1.4.0.137
Wso2Open Banking Km Version >= 1.5.0 < 1.5.0.127
Wso2Traffic Manager Version >= 4.5.0 < 4.5.0.43
Wso2Traffic Manager Version >= 4.6.0 < 4.6.0.8
Wso2Universal Gateway Version >= 4.5.0 < 4.5.0.44
Wso2Universal Gateway Version >= 4.6.0 < 4.6.0.8
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.301
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ed10eef1-636d-4fbe-9993-6890dfa878f8 9.4 3.9 5.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/
Vendor Advisory