What is CVE-2025-15039?
CVE-2025-15039 is a vulnerability classified as Protection Mechanism Failure, affecting WSO2 Identity Server (affected versions: 5.7.0 – < 5.7.0.130, 5.8.0 – < 5.8.0.113, and other affected versions), WSO2 API Manager (affected versions: 2.6.0 – < 2.6.0.150, 3.0.0 – < 3.0.0.180, and other affected versions), WSO2 Open Banking AM (affected versions: 1.4.0 – < 1.4.0.143, 1.5.0 – < 1.5.0.144, and other affected versions), and 7 more products. This vulnerability is rated Critical, with a CVSS score of 9.4. Current sources do not report this vulnerability as exploited.