{"id":"CVE-2025-15039","title":"The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured","summary":"The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows…","severity":"critical","cvss":9.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","cwe":["CWE-693"],"vendor":"wso2","product":"api_control_plane","affected":["api_control_plane >= 4.5.0, < 4.5.0.45","api_control_plane >= 4.6.0, < 4.6.0.9","api_manager >= 2.6.0, < 2.6.0.150","api_manager >= 3.0.0, < 3.0.0.180","api_manager >= 3.1.0, < 3.1.0.356","api_manager >= 3.2.0, < 3.2.0.460","api_manager >= 3.2.1, < 3.2.1.79","api_manager >= 4.0.0, < 4.0.0.381","api_manager >= 4.1.0, < 4.1.0.244","api_manager >= 4.2.0, < 4.2.0.184","api_manager >= 4.3.0, < 4.3.0.95","api_manager >= 4.4.0, < 4.4.0.59","api_manager >= 4.5.0, < 4.5.0.44","api_manager >= 4.6.0, < 4.6.0.8","identity_server >= 5.7.0, < 5.7.0.130","identity_server >= 5.8.0, < 5.8.0.133","identity_server >= 5.9.0, < 5.9.0.173","identity_server >= 5.10.0, < 5.10.0.385","identity_server >= 5.11.0, < 5.11.0.432","identity_server >= 6.0.0, < 6.0.0.259","identity_server >= 6.1.0, < 6.1.0.260","identity_server >= 7.0.0, < 7.0.0.138","identity_server >= 7.1.0, < 7.1.0.49","identity_server >= 7.2.0, < 7.2.0.7","identity_server_as_key_manager >= 5.7.0, < 5.7.0.129","identity_server_as_key_manager >= 5.9.0, < 5.9.0.179","identity_server_as_key_manager >= 5.10.0, < 5.10.0.376","open_banking_am >= 1.4.0, < 1.4.0.143","open_banking_am >= 1.5.0, < 1.5.0.144","open_banking_am >= 2.0.0, < 2.0.0.405","open_banking_iam >= 2.0.0, < 2.0.0.425","open_banking_km >= 1.4.0, < 1.4.0.137","open_banking_km >= 1.5.0, < 1.5.0.127","traffic_manager >= 4.5.0, < 4.5.0.43","traffic_manager >= 4.6.0, < 4.6.0.8","universal_gateway >= 4.5.0, < 4.5.0.44","universal_gateway >= 4.6.0, < 4.6.0.8"],"patched":["api_control_plane 4.6.0.9","api_manager 4.6.0.8","identity_server 7.2.0.7","identity_server_as_key_manager 5.10.0.376","open_banking_am 2.0.0.405","open_banking_iam 2.0.0.425","open_banking_km 1.5.0.127","traffic_manager 4.6.0.8","universal_gateway 4.6.0.8"],"published":"2026-08-06","updated":"2026-09-29","sourceUpdated":"2026-09-29T14:10:00.117","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15039","references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/","label":"ed10eef1-636d-4fbe-9993-6890dfa878f8"}],"tags":["nvd"],"epss":0.00668,"epssPercentile":0.49934,"ingestedAt":"2026-09-29T14:36:14.078Z","slug":"CVE-2025-15039","body":"## Overview\n\nThe Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.\n\nSuccessful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.\n\n## Affected\n\n- `api_control_plane >= 4.5.0, < 4.5.0.45`\n- `api_control_plane >= 4.6.0, < 4.6.0.9`\n- `api_manager >= 2.6.0, < 2.6.0.150`\n- `api_manager >= 3.0.0, < 3.0.0.180`\n- `api_manager >= 3.1.0, < 3.1.0.356`\n- `api_manager >= 3.2.0, < 3.2.0.460`\n- `api_manager >= 3.2.1, < 3.2.1.79`\n- `api_manager >= 4.0.0, < 4.0.0.381`\n- `api_manager >= 4.1.0, < 4.1.0.244`\n- `api_manager >= 4.2.0, < 4.2.0.184`\n- `api_manager >= 4.3.0, < 4.3.0.95`\n- `api_manager >= 4.4.0, < 4.4.0.59`\n- `api_manager >= 4.5.0, < 4.5.0.44`\n- `api_manager >= 4.6.0, < 4.6.0.8`\n- `identity_server >= 5.7.0, < 5.7.0.130`\n- `identity_server >= 5.8.0, < 5.8.0.133`\n- `identity_server >= 5.9.0, < 5.9.0.173`\n- `identity_server >= 5.10.0, < 5.10.0.385`\n- `identity_server >= 5.11.0, < 5.11.0.432`\n- `identity_server >= 6.0.0, < 6.0.0.259`\n- `identity_server >= 6.1.0, < 6.1.0.260`\n- `identity_server >= 7.0.0, < 7.0.0.138`\n- `identity_server >= 7.1.0, < 7.1.0.49`\n- `identity_server >= 7.2.0, < 7.2.0.7`\n- `identity_server_as_key_manager >= 5.7.0, < 5.7.0.129`\n- `identity_server_as_key_manager >= 5.9.0, < 5.9.0.179`\n- `identity_server_as_key_manager >= 5.10.0, < 5.10.0.376`\n- `open_banking_am >= 1.4.0, < 1.4.0.143`\n- `open_banking_am >= 1.5.0, < 1.5.0.144`\n- `open_banking_am >= 2.0.0, < 2.0.0.405`\n- `open_banking_iam >= 2.0.0, < 2.0.0.425`\n- `open_banking_km >= 1.4.0, < 1.4.0.137`\n- `open_banking_km >= 1.5.0, < 1.5.0.127`\n- `traffic_manager >= 4.5.0, < 4.5.0.43`\n- `traffic_manager >= 4.6.0, < 4.6.0.8`\n- `universal_gateway >= 4.5.0, < 4.5.0.44`\n- `universal_gateway >= 4.6.0, < 4.6.0.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `api_control_plane 4.6.0.9`\n- `api_manager 4.6.0.8`\n- `identity_server 7.2.0.7`\n- `identity_server_as_key_manager 5.10.0.376`\n- `open_banking_am 2.0.0.405`\n- `open_banking_iam 2.0.0.425`\n- `open_banking_km 1.5.0.127`\n- `traffic_manager 4.6.0.8`\n- `universal_gateway 4.6.0.8`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":51.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}