CVE-2025-15039Critical· 9.4▾ MidnightThe Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.
Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
api_control_plane >= 4.5.0, < 4.5.0.45api_control_plane >= 4.6.0, < 4.6.0.9api_manager >= 2.6.0, < 2.6.0.150api_manager >= 3.0.0, < 3.0.0.180api_manager >= 3.1.0, < 3.1.0.356api_manager >= 3.2.0, < 3.2.0.460api_manager >= 3.2.1, < 3.2.1.79api_manager >= 4.0.0, < 4.0.0.381api_manager >= 4.1.0, < 4.1.0.244api_manager >= 4.2.0, < 4.2.0.184api_manager >= 4.3.0, < 4.3.0.95api_manager >= 4.4.0, < 4.4.0.59api_manager >= 4.5.0, < 4.5.0.44api_manager >= 4.6.0, < 4.6.0.8identity_server >= 5.7.0, < 5.7.0.130identity_server >= 5.8.0, < 5.8.0.133identity_server >= 5.9.0, < 5.9.0.173identity_server >= 5.10.0, < 5.10.0.385identity_server >= 5.11.0, < 5.11.0.432identity_server >= 6.0.0, < 6.0.0.259identity_server >= 6.1.0, < 6.1.0.260identity_server >= 7.0.0, < 7.0.0.138identity_server >= 7.1.0, < 7.1.0.49identity_server >= 7.2.0, < 7.2.0.7identity_server_as_key_manager >= 5.7.0, < 5.7.0.129identity_server_as_key_manager >= 5.9.0, < 5.9.0.179identity_server_as_key_manager >= 5.10.0, < 5.10.0.376open_banking_am >= 1.4.0, < 1.4.0.143open_banking_am >= 1.5.0, < 1.5.0.144open_banking_am >= 2.0.0, < 2.0.0.405open_banking_iam >= 2.0.0, < 2.0.0.425open_banking_km >= 1.4.0, < 1.4.0.137open_banking_km >= 1.5.0, < 1.5.0.127traffic_manager >= 4.5.0, < 4.5.0.43traffic_manager >= 4.6.0, < 4.6.0.8universal_gateway >= 4.5.0, < 4.5.0.44universal_gateway >= 4.6.0, < 4.6.0.8Upgrade past the affected range:
api_control_plane 4.6.0.9api_manager 4.6.0.8identity_server 7.2.0.7identity_server_as_key_manager 5.10.0.376open_banking_am 2.0.0.405open_banking_iam 2.0.0.425open_banking_km 1.5.0.127traffic_manager 4.6.0.8universal_gateway 4.6.0.8Connected by shared product, vendor, weakness, or advisory.
CVE-2024-6832Medium· 5.9The account locking mechanism fails to trigger when secondary user stores are inaccessible
CVE-2025-13394Medium· 5.4The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks
CVE-2025-9804Critical· 9.6An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs
CVE-2026-5430Critical· 10.0The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported
CVE-2026-3416Medium· 5.9The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation
CVE-2025-12737High· 8.4The administrative operations within the Carbon Console do not adequately validate specific user-supplied input