Conditional Authentication Bypass in WSO2 Product
CVE-2025-15039
9.4CRITICAL
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2025-15039?
A vulnerability exists in WSO2 Identity Server's Conditional Authentication mechanism, which fails to properly enforce all required authentication steps. This misconfiguration allows attackers to bypass intermediate authentication challenges when a certain multi-step pattern and specific event callbacks are involved. As a result, a malicious actor could potentially gain unauthorized access to user accounts by successfully navigating through the required preceding authentication steps, given that the targeted user has an affected authenticator enrolled.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.45
WSO2 API Control Plane 4.6.0 < 4.6.0.9
WSO2 API Manager 2.6.0 < 2.6.0.150
