


Perceptive Security
SOC/SIEM Consultancy

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific m…
Published:
6 August 2026 at 00:00:00
Alert date:
6 August 2026 at 11:03:45
Source:
nvd.nist.gov
Identity & Access, Web Technologies, Enterprise Applications
CVE-2025-15039 affects WSO2's Conditional Authentication (Adaptive Authentication) script, which fails to correctly enforce the completion of all required authentication steps in specific multi-step configurations. An attacker can bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation grants unauthorized access to targeted user accounts. The vulnerability requires a specific set of conditions: a secondary authenticator in the login flow, particular event callbacks configured in the script, the targeted user having an impacted authenticator enrolled, and the attacker completing prior authentication steps. This is a logic flaw in the authentication flow rather than a code injection issue. WSO2 has published a security advisory addressing this issue. The vulnerability poses a high risk to organizations using WSO2 identity management solutions with adaptive authentication enabled.
Technical details
Mitigation steps:
Affected products:
WSO2 Conditional Authentication
WSO2 Adaptive Authentication
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-15039
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4973/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
