๐Ÿ” CVE Alert

CVE-2025-15039

CRITICAL 9.4

Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products

CVSS Score
9.4
EPSS Score
0.0%
EPSS Percentile
0th

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

CWE CWE-693
Vendor wso2
Product wso2 identity server
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for wso2 wso2 identity server

Be the first to know when new critical vulnerabilities affecting wso2 wso2 identity server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

WSO2 / WSO2 Identity Server
5.7.0 < 5.7.0.130 5.8.0 < 5.8.0.113 5.9.0 < 5.9.0.173 5.10.0 < 5.10.0.385 5.11.0 < 5.11.0.432 6.0.0 < 6.0.0.259 6.1.0 < 6.1.0.260 7.0.0 < 7.0.0.138 7.1.0 < 7.1.0.45 7.1.0 < 7.1.0.49 7.2.0 < 7.2.0.7
WSO2 / WSO2 API Manager
2.6.0 < 2.6.0.150 3.0.0 < 3.0.0.180 3.1.0 < 3.1.0.356 3.2.0 < 3.2.0.460 3.2.1 < 3.2.1.79 4.0.0 < 4.0.0.381 4.1.0 < 4.1.0.244 4.2.0 < 4.2.0.184 4.3.0 < 4.3.0.95 4.4.0 < 4.4.0.59 4.5.0 < 4.5.0.44 4.6.0 < 4.6.0.8
WSO2 / WSO2 Open Banking AM
1.4.0 < 1.4.0.143 1.5.0 < 1.5.0.144 2.0.0 < 2.0.0.405
WSO2 / WSO2 Open Banking IAM
2.0.0 < 2.0.0.425
WSO2 / WSO2 Traffic Manager
4.5.0 < 4.5.0.43 4.6.0 < 4.6.0.8
WSO2 / WSO2 Universal Gateway
4.5.0 < 4.5.0.43 4.5.0 < 4.5.0.44 4.6.0 < 4.6.0.8
WSO2 / WSO2 API Control Plane
4.5.0 < 4.5.0.45 4.6.0 < 4.6.0.9
WSO2 / WSO2 Identity Server as Key Manager
5.7.0 < 5.7.0.129 5.9.0 < 5.9.0.179 5.10.0 < 5.10.0.376
WSO2 / WSO2 Open Banking KM
1.4.0 < 1.4.0.137 1.5.0 < 1.5.0.127
WSO2 / WSO2 Carbon Identity Application Authentication Framework
5.12.153 < 5.12.153.66 5.12.387 < 5.12.387.48 5.14.97 < 5.14.97.94 5.17.5 < 5.17.5.337 5.17.118 < 5.17.118.24 5.18.187 < 5.18.187.334 5.18.248 < 5.18.248.34 5.23.8 < 5.23.8.221 5.24.8 < 5.24.8.29 5.25.92 < 5.25.92.177 5.25.705 < 5.25.705.23 5.25.713 < 5.25.713.12 5.25.724 < 5.25.724.8 5.25.736 < 5.25.736.3 7.0.78 < 7.0.78.171 7.8.23 < 7.8.23.95 7.8.586 < 7.8.586.21

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.docs.wso2.com: https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/