Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-15039?

CVE-2025-15039 is a vulnerability classified as Protection Mechanism Failure, affecting WSO2 Identity Server (affected versions: 5.7.0 – < 5.7.0.130, 5.8.0 – < 5.8.0.113, and other affected versions), WSO2 API Manager (affected versions: 2.6.0 – < 2.6.0.150, 3.0.0 – < 3.0.0.180, and other affected versions), WSO2 Open Banking AM (affected versions: 1.4.0 – < 1.4.0.143, 1.5.0 – < 1.5.0.144, and other affected versions), and 7 more products. This vulnerability is rated Critical, with a CVSS score of 9.4. Current sources do not report this vulnerability as exploited.

The analysis could not be completed. The original vulnerability data remains available below.

Overview

Original source data

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.

Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Affected products and scope

The analysis could not be completed. The original vulnerability data remains available below.

Technical details

The analysis could not be completed. The original vulnerability data remains available below.

Exploitability

The analysis could not be completed. The original vulnerability data remains available below.

Technical impact

The analysis could not be completed. The original vulnerability data remains available below.

Business impact

The analysis could not be completed. The original vulnerability data remains available below.

Remediation

The analysis could not be completed. The original vulnerability data remains available below.

Detection

The analysis could not be completed. The original vulnerability data remains available below.
Sources (6)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan