top of page
perceptive_background_267k.jpg

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific m…

Published:

5 August 2026 at 22:00:00

Alert date:

6 August 2026 at 09:03:45

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies, Enterprise Applications

CVE-2025-15039 affects WSO2's Conditional Authentication (Adaptive Authentication) script, which fails to correctly enforce the completion of all required authentication steps in specific multi-step configurations. An attacker can bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation grants unauthorized access to targeted user accounts. The vulnerability requires a specific set of conditions: a secondary authenticator in the login flow, particular event callbacks configured in the script, the targeted user having an impacted authenticator enrolled, and the attacker completing prior authentication steps. This is a logic flaw in the authentication flow rather than a code injection issue. WSO2 has published a security advisory addressing this issue. The vulnerability poses a high risk to organizations using WSO2 identity management solutions with adaptive authentication enabled.

Technical details

Mitigation steps:

Affected products:

WSO2 Conditional Authentication
WSO2 Adaptive Authentication

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page