Description
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.

Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Published: 2026-08-06
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Conditional Authentication script used by several WSO2 products fails to enforce the completion of all required authentication steps when a specific multi‑step pattern is configured. As a result, an attacker can bypass intermediate authentication challenges and gain unauthorized access to a target user’s account. This flaw directly enables account takeover and is reflected by the high CVSS score of 9.4, indicating a serious risk to confidentiality and integrity.

Affected Systems

The vulnerability affects multiple WSO2 products, including the API Control Plane, API Manager, Carbon Identity Application Authentication Framework, Identity Server, Identity Server as Key Manager, Open Banking API Manager, Open Banking IAM, Open Banking KM, Traffic Manager, and Universal Gateway. Version information is not available from the current data, so all current releases are potentially impacted unless patched.

Risk and Exploitability

The CVSS score of 9.4 classifies this as critical, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. An attacker can exploit the flaw by engaging the normal login flow over the internet, completing any required preceding authentication steps, and then manipulating the callback mechanism to bypass subsequent challenges. The attack requires that the user has a vulnerable authenticator enrolled and that the application uses the conditioned authentication script configured with the specific callbacks.

Generated by OpenCVE AI on August 6, 2026 at 09:22 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/#solution


OpenCVE Recommended Actions

  • Apply the official fix by following WSO2’s solution instructions and upgrading to the patched versions of the affected products.
  • Disable the vulnerable secondary authenticator and reconfigure the conditional authentication script to require completion of all authentication steps before granting access.
  • Monitor authentication logs for anomalous patterns and enforce account lockout policies to reduce the impact of any attempted takeovers.

Generated by OpenCVE AI on August 6, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 api Control Plane
Wso2 api Manager
Wso2 carbon Identity Application Authentication Framework
Wso2 identity Server
Wso2 identity Server As Key Manager
Wso2 open Banking Am
Wso2 open Banking Iam
Wso2 open Banking Km
Wso2 traffic Manager
Wso2 universal Gateway
Vendors & Products Wso2 api Control Plane
Wso2 api Manager
Wso2 carbon Identity Application Authentication Framework
Wso2 identity Server
Wso2 identity Server As Key Manager
Wso2 open Banking Am
Wso2 open Banking Iam
Wso2 open Banking Km
Wso2 traffic Manager
Wso2 universal Gateway

Thu, 06 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Title Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
First Time appeared Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Wso2 wso2 Carbon Identity Application Authentication Framework
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam
Wso2 wso2 Open Banking Km
Wso2 wso2 Traffic Manager
Wso2 wso2 Universal Gateway
Weaknesses CWE-693
CPEs cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_carbon_identity_application_authentication_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_identity_server_as_key_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_open_banking_am:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_open_banking_iam:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_open_banking_km:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Wso2 wso2 Carbon Identity Application Authentication Framework
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam
Wso2 wso2 Open Banking Km
Wso2 wso2 Traffic Manager
Wso2 wso2 Universal Gateway
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Wso2 Api Control Plane Api Manager Carbon Identity Application Authentication Framework Identity Server Identity Server As Key Manager Open Banking Am Open Banking Iam Open Banking Km Traffic Manager Universal Gateway Wso2 Api Control Plane Wso2 Api Manager Wso2 Carbon Identity Application Authentication Framework Wso2 Identity Server Wso2 Identity Server As Key Manager Wso2 Open Banking Am Wso2 Open Banking Iam Wso2 Open Banking Km Wso2 Traffic Manager Wso2 Universal Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-06T12:31:43.779Z

Reserved: 2025-12-23T08:27:22.275Z

Link: CVE-2025-15039

cve-icon Vulnrichment

Updated: 2026-08-06T12:31:40.686Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:15:12Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure