9.4
CVE-2025-15039
- EPSS 0.37%
- Veröffentlicht 06.08.2026 08:16:29
- Zuletzt bearbeitet 12.08.2026 19:32:37
- CVE-Watchlists
- Unerledigt
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2 ≫ Api Control Plane Version >= 4.5.0 < 4.5.0.45
Wso2 ≫ Api Control Plane Version >= 4.6.0 < 4.6.0.9
Wso2 ≫ Api Manager Version >= 2.6.0 < 2.6.0.150
Wso2 ≫ Api Manager Version >= 3.0.0 < 3.0.0.180
Wso2 ≫ Api Manager Version >= 3.1.0 < 3.1.0.356
Wso2 ≫ Api Manager Version >= 3.2.0 < 3.2.0.460
Wso2 ≫ Api Manager Version >= 3.2.1 < 3.2.1.79
Wso2 ≫ Api Manager Version >= 4.0.0 < 4.0.0.381
Wso2 ≫ Api Manager Version >= 4.1.0 < 4.1.0.244
Wso2 ≫ Api Manager Version >= 4.2.0 < 4.2.0.184
Wso2 ≫ Api Manager Version >= 4.3.0 < 4.3.0.95
Wso2 ≫ Api Manager Version >= 4.4.0 < 4.4.0.59
Wso2 ≫ Api Manager Version >= 4.5.0 < 4.5.0.44
Wso2 ≫ Api Manager Version >= 4.6.0 < 4.6.0.8
Wso2 ≫ Identity Server Version >= 5.7.0 < 5.7.0.130
Wso2 ≫ Identity Server Version >= 5.8.0 < 5.8.0.133
Wso2 ≫ Identity Server Version >= 5.9.0 < 5.9.0.173
Wso2 ≫ Identity Server Version >= 5.10.0 < 5.10.0.385
Wso2 ≫ Identity Server Version >= 5.11.0 < 5.11.0.432
Wso2 ≫ Identity Server Version >= 6.0.0 < 6.0.0.259
Wso2 ≫ Identity Server Version >= 6.1.0 < 6.1.0.260
Wso2 ≫ Identity Server Version >= 7.0.0 < 7.0.0.138
Wso2 ≫ Identity Server Version >= 7.1.0 < 7.1.0.49
Wso2 ≫ Identity Server Version >= 7.2.0 < 7.2.0.7
Wso2 ≫ Identity Server As Key Manager Version >= 5.7.0 < 5.7.0.129
Wso2 ≫ Identity Server As Key Manager Version >= 5.9.0 < 5.9.0.179
Wso2 ≫ Identity Server As Key Manager Version >= 5.10.0 < 5.10.0.376
Wso2 ≫ Open Banking Am Version >= 1.4.0 < 1.4.0.143
Wso2 ≫ Open Banking Am Version >= 1.5.0 < 1.5.0.144
Wso2 ≫ Open Banking Am Version >= 2.0.0 < 2.0.0.405
Wso2 ≫ Open Banking Iam Version >= 2.0.0 < 2.0.0.425
Wso2 ≫ Open Banking Km Version >= 1.4.0 < 1.4.0.137
Wso2 ≫ Open Banking Km Version >= 1.5.0 < 1.5.0.127
Wso2 ≫ Traffic Manager Version >= 4.5.0 < 4.5.0.43
Wso2 ≫ Traffic Manager Version >= 4.6.0 < 4.6.0.8
Wso2 ≫ Universal Gateway Version >= 4.5.0 < 4.5.0.44
Wso2 ≫ Universal Gateway Version >= 4.6.0 < 4.6.0.8
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.301 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 9.4 | 3.9 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
|
CWE-693 Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/