
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15039 is a critical authentication bypass vulnerability in WSO2's Conditional Authentication (Adaptive Authentication) script that fails to correctly enforce the completion of all required multi-step authentication challenges. Successful exploitation allows an unauthenticated attacker to gain unauthorized access to a targeted user account under specific configuration conditions. The vulnerability affects a broad range of WSO2 products including Identity Server (5.7.0–7.2.x), API Manager (2.6.0–4.6.x), API Control Plane (4.5.0–4.6.x), Universal Gateway, Traffic Manager, Open Banking AM/IAM/KM, and Identity Server as Key Manager. It was published on August 6, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 9.4 (Critical) (GitHub Advisory, WSO2 Advisory).
The root cause is classified as CWE-693 (Protection Mechanism Failure): the Conditional Authentication script does not properly track or enforce the completion of all required authentication steps when a specific multi-step pattern is configured. An attacker exploits how the script handles event callbacks and re-execution of authentication steps — by manipulating the callback flow, intermediate authentication challenges (e.g., a secondary MFA factor) can be skipped or bypassed. Exploitation requires no privileges and no user interaction, and is network-accessible with low attack complexity, but is conditional on a specific application login flow configuration: the flow must include a particular secondary authenticator, the Conditional Authentication script must use specific event callbacks with step re-execution, and the targeted user must have one of the impacted authenticators enrolled (GitHub Advisory, WSO2 Advisory).
Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account, bypassing multi-factor or adaptive authentication controls. The impact includes high confidentiality and integrity compromise — an attacker with account access could read sensitive data, modify account settings, or perform actions on behalf of the victim. Availability impact is rated low. Given that WSO2 Identity Server and API Manager are often used as central identity and access management platforms, account takeover could enable lateral movement into downstream applications and APIs protected by the compromised identity provider (GitHub Advisory, WSO2 Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" at this time, though the vulnerability is rated "automatable" with "total" technical impact. The EPSS score is approximately 0.39%, placing it in the 30th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
/commonauth, /samlsso, /oauth2/authorize) with anomalous callback parameters or step re-execution patterns from a single source IP.wso2carbon.log) showing abnormal Conditional Authentication script execution paths, particularly repeated invocations of step callbacks without expected authenticator completion events.WSO2 released patches on August 6, 2026 (advisory WSO2-2025-4973). Organizations should update to the following fixed versions or later: Identity Server ≥ 7.2.0.7, 7.1.0.49, 7.0.0.138, 6.1.0.260, 6.0.0.259, 5.11.0.432, 5.10.0.385, 5.9.0.173, 5.8.0.133, 5.7.0.130; API Manager ≥ 4.6.0.8, 4.5.0.44, 4.4.0.59, 4.3.0.95, 4.2.0.184, 4.1.0.244, 4.0.0.381, 3.2.0.460, 3.1.0.356, 3.0.0.180, 2.6.0.150; API Control Plane ≥ 4.6.0.9, 4.5.0.45; and corresponding fixed versions for Universal Gateway, Traffic Manager, Open Banking AM/IAM/KM, and Identity Server as Key Manager. As a workaround, review and validate all Conditional Authentication script configurations to ensure event callbacks and step re-execution patterns strictly enforce completion of all required authentication steps. Implement server-side session validation and strict authentication step sequencing controls where possible (WSO2 Advisory, GitHub Advisory).
Security news outlet SecurityOnline.info covered the vulnerability under the headline "WSO2 Account Takeover Flaws" shortly after disclosure (SecurityOnline). The vulnerability was also discussed on Reddit's r/pwnhub CVE daily brief and noted on Bluesky by security community accounts. No major vendor statements beyond WSO2's own advisory have been identified, and no prominent independent researcher commentary has been published at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."