CVE-2025-15039: WSO2 API Control Plane

Critical severity, CVSS 9.4. EPSS: 0.7% chance of exploitation in the next 30 days.

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Affected products

  • WSO2 API Control Plane: from 4.5.0, before 4.5.0.45 (fixed in 4.5.0.45); from 4.6.0, before 4.6.0.9 (fixed in 4.6.0.9)
  • WSO2 API Manager: from 2.6.0, before 2.6.0.150 (fixed in 2.6.0.150); from 3.0.0, before 3.0.0.180 (fixed in 3.0.0.180); from 3.1.0, before 3.1.0.356 (fixed in 3.1.0.356); from 3.2.0, before 3.2.0.460 (fixed in 3.2.0.460); from 3.2.1, before 3.2.1.79 (fixed in 3.2.1.79); from 4.0.0, before 4.0.0.381 (fixed in 4.0.0.381); …
  • WSO2 Identity Server: from 5.7.0, before 5.7.0.130 (fixed in 5.7.0.130); from 5.8.0, before 5.8.0.133 (fixed in 5.8.0.133); from 5.9.0, before 5.9.0.173 (fixed in 5.9.0.173); from 5.10.0, before 5.10.0.385 (fixed in 5.10.0.385); from 5.11.0, before 5.11.0.432 (fixed in 5.11.0.432); from 6.0.0, before 6.0.0.259 (fixed in 6.0.0.259); …
  • WSO2 Identity Server As Key Manager: from 5.7.0, before 5.7.0.129 (fixed in 5.7.0.129); from 5.9.0, before 5.9.0.179 (fixed in 5.9.0.179); from 5.10.0, before 5.10.0.376 (fixed in 5.10.0.376)
  • WSO2 Open Banking AM: from 1.4.0, before 1.4.0.143 (fixed in 1.4.0.143); from 1.5.0, before 1.5.0.144 (fixed in 1.5.0.144); from 2.0.0, before 2.0.0.405 (fixed in 2.0.0.405)
  • WSO2 Open Banking Iam: from 2.0.0, before 2.0.0.425 (fixed in 2.0.0.425)
  • WSO2 Open Banking Km: from 1.4.0, before 1.4.0.137 (fixed in 1.4.0.137); from 1.5.0, before 1.5.0.127 (fixed in 1.5.0.127)
  • WSO2 Traffic Manager: from 4.5.0, before 4.5.0.43 (fixed in 4.5.0.43); from 4.6.0, before 4.6.0.8 (fixed in 4.6.0.8)
  • WSO2 Universal Gateway: from 4.5.0, before 4.5.0.44 (fixed in 4.5.0.44); from 4.6.0, before 4.6.0.8 (fixed in 4.6.0.8)

Published 2026-08-06. Last modified 2026-09-29.