Impact
The Conditional Authentication script used by several WSO2 products fails to enforce the completion of all required authentication steps when a specific multi‑step pattern is configured. As a result, an attacker can bypass intermediate authentication challenges and gain unauthorized access to a target user’s account. This flaw directly enables account takeover and is reflected by the high CVSS score of 9.4, indicating a serious risk to confidentiality and integrity.
Affected Systems
The vulnerability affects multiple WSO2 products, including the API Control Plane, API Manager, Carbon Identity Application Authentication Framework, Identity Server, Identity Server as Key Manager, Open Banking API Manager, Open Banking IAM, Open Banking KM, Traffic Manager, and Universal Gateway. Version information is not available from the current data, so all current releases are potentially impacted unless patched.
Risk and Exploitability
The CVSS score of 9.4 classifies this as critical, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. An attacker can exploit the flaw by engaging the normal login flow over the internet, completing any required preceding authentication steps, and then manipulating the callback mechanism to bypass subsequent challenges. The attack requires that the user has a vulnerable authenticator enrolled and that the application uses the conditioned authentication script configured with the specific callbacks.
OpenCVE Enrichment