---
id: CVE-2025-15039
title: >-
  The Conditional Authentication (Adaptive Authentication) script does not
  correctly enforce the completion of all required authentication steps when a
  specific multi-step pattern involving certain authenticators is configured
summary: >-
  The Conditional Authentication (Adaptive Authentication) script does not
  correctly enforce the completion of all required authentication steps when a
  specific multi-step pattern involving certain authenticators is configured.
  This allows…
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-693
vendor: wso2
product: api_control_plane
affected:
  - 'api_control_plane >= 4.5.0, < 4.5.0.45'
  - 'api_control_plane >= 4.6.0, < 4.6.0.9'
  - 'api_manager >= 2.6.0, < 2.6.0.150'
  - 'api_manager >= 3.0.0, < 3.0.0.180'
  - 'api_manager >= 3.1.0, < 3.1.0.356'
  - 'api_manager >= 3.2.0, < 3.2.0.460'
  - 'api_manager >= 3.2.1, < 3.2.1.79'
  - 'api_manager >= 4.0.0, < 4.0.0.381'
  - 'api_manager >= 4.1.0, < 4.1.0.244'
  - 'api_manager >= 4.2.0, < 4.2.0.184'
  - 'api_manager >= 4.3.0, < 4.3.0.95'
  - 'api_manager >= 4.4.0, < 4.4.0.59'
  - 'api_manager >= 4.5.0, < 4.5.0.44'
  - 'api_manager >= 4.6.0, < 4.6.0.8'
  - 'identity_server >= 5.7.0, < 5.7.0.130'
  - 'identity_server >= 5.8.0, < 5.8.0.133'
  - 'identity_server >= 5.9.0, < 5.9.0.173'
  - 'identity_server >= 5.10.0, < 5.10.0.385'
  - 'identity_server >= 5.11.0, < 5.11.0.432'
  - 'identity_server >= 6.0.0, < 6.0.0.259'
  - 'identity_server >= 6.1.0, < 6.1.0.260'
  - 'identity_server >= 7.0.0, < 7.0.0.138'
  - 'identity_server >= 7.1.0, < 7.1.0.49'
  - 'identity_server >= 7.2.0, < 7.2.0.7'
  - 'identity_server_as_key_manager >= 5.7.0, < 5.7.0.129'
  - 'identity_server_as_key_manager >= 5.9.0, < 5.9.0.179'
  - 'identity_server_as_key_manager >= 5.10.0, < 5.10.0.376'
  - 'open_banking_am >= 1.4.0, < 1.4.0.143'
  - 'open_banking_am >= 1.5.0, < 1.5.0.144'
  - 'open_banking_am >= 2.0.0, < 2.0.0.405'
  - 'open_banking_iam >= 2.0.0, < 2.0.0.425'
  - 'open_banking_km >= 1.4.0, < 1.4.0.137'
  - 'open_banking_km >= 1.5.0, < 1.5.0.127'
  - 'traffic_manager >= 4.5.0, < 4.5.0.43'
  - 'traffic_manager >= 4.6.0, < 4.6.0.8'
  - 'universal_gateway >= 4.5.0, < 4.5.0.44'
  - 'universal_gateway >= 4.6.0, < 4.6.0.8'
patched:
  - api_control_plane 4.6.0.9
  - api_manager 4.6.0.8
  - identity_server 7.2.0.7
  - identity_server_as_key_manager 5.10.0.376
  - open_banking_am 2.0.0.405
  - open_banking_iam 2.0.0.425
  - open_banking_km 1.5.0.127
  - traffic_manager 4.6.0.8
  - universal_gateway 4.6.0.8
published: '2026-08-06'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:10:00.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15039'
references:
  - url: >-
      https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/
    label: ed10eef1-636d-4fbe-9993-6890dfa878f8
tags:
  - nvd
epss: 0.00668
epssPercentile: 0.49934
ingestedAt: '2026-09-29T14:36:14.078Z'
---

## Overview

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.

Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

## Affected

- `api_control_plane >= 4.5.0, < 4.5.0.45`
- `api_control_plane >= 4.6.0, < 4.6.0.9`
- `api_manager >= 2.6.0, < 2.6.0.150`
- `api_manager >= 3.0.0, < 3.0.0.180`
- `api_manager >= 3.1.0, < 3.1.0.356`
- `api_manager >= 3.2.0, < 3.2.0.460`
- `api_manager >= 3.2.1, < 3.2.1.79`
- `api_manager >= 4.0.0, < 4.0.0.381`
- `api_manager >= 4.1.0, < 4.1.0.244`
- `api_manager >= 4.2.0, < 4.2.0.184`
- `api_manager >= 4.3.0, < 4.3.0.95`
- `api_manager >= 4.4.0, < 4.4.0.59`
- `api_manager >= 4.5.0, < 4.5.0.44`
- `api_manager >= 4.6.0, < 4.6.0.8`
- `identity_server >= 5.7.0, < 5.7.0.130`
- `identity_server >= 5.8.0, < 5.8.0.133`
- `identity_server >= 5.9.0, < 5.9.0.173`
- `identity_server >= 5.10.0, < 5.10.0.385`
- `identity_server >= 5.11.0, < 5.11.0.432`
- `identity_server >= 6.0.0, < 6.0.0.259`
- `identity_server >= 6.1.0, < 6.1.0.260`
- `identity_server >= 7.0.0, < 7.0.0.138`
- `identity_server >= 7.1.0, < 7.1.0.49`
- `identity_server >= 7.2.0, < 7.2.0.7`
- `identity_server_as_key_manager >= 5.7.0, < 5.7.0.129`
- `identity_server_as_key_manager >= 5.9.0, < 5.9.0.179`
- `identity_server_as_key_manager >= 5.10.0, < 5.10.0.376`
- `open_banking_am >= 1.4.0, < 1.4.0.143`
- `open_banking_am >= 1.5.0, < 1.5.0.144`
- `open_banking_am >= 2.0.0, < 2.0.0.405`
- `open_banking_iam >= 2.0.0, < 2.0.0.425`
- `open_banking_km >= 1.4.0, < 1.4.0.137`
- `open_banking_km >= 1.5.0, < 1.5.0.127`
- `traffic_manager >= 4.5.0, < 4.5.0.43`
- `traffic_manager >= 4.6.0, < 4.6.0.8`
- `universal_gateway >= 4.5.0, < 4.5.0.44`
- `universal_gateway >= 4.6.0, < 4.6.0.8`

## Remediation

Upgrade past the affected range:

- `api_control_plane 4.6.0.9`
- `api_manager 4.6.0.8`
- `identity_server 7.2.0.7`
- `identity_server_as_key_manager 5.10.0.376`
- `open_banking_am 2.0.0.405`
- `open_banking_iam 2.0.0.425`
- `open_banking_km 1.5.0.127`
- `traffic_manager 4.6.0.8`
- `universal_gateway 4.6.0.8`
