Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-15039

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-693 Fallo del mecanismo de protección
Fecha de publicación:
06/08/2026
Última modificación:
12/08/2026

Descripción

*** Pendiente de traducción *** The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps.<br /> <br /> Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* 4.5.0 (incluyendo) 4.5.0.45 (excluyendo)
cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:* 4.6.0 (incluyendo) 4.6.0.9 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 2.6.0 (incluyendo) 2.6.0.150 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 3.0.0 (incluyendo) 3.0.0.180 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 3.1.0 (incluyendo) 3.1.0.356 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 3.2.0 (incluyendo) 3.2.0.460 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 3.2.1 (incluyendo) 3.2.1.79 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.0.0 (incluyendo) 4.0.0.381 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.1.0 (incluyendo) 4.1.0.244 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.2.0 (incluyendo) 4.2.0.184 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.3.0 (incluyendo) 4.3.0.95 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.4.0 (incluyendo) 4.4.0.59 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.5.0 (incluyendo) 4.5.0.44 (excluyendo)
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:* 4.6.0 (incluyendo) 4.6.0.8 (excluyendo)
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* 5.7.0 (incluyendo) 5.7.0.130 (excluyendo)