CVE-2025-15039 | WSO2 API Control Plane Conditional Authentication improper authorization

SecurityVulns

A vulnerability was found in WSO2 API Control Plane, API Manager, Carbon Identity Application Authentication Framework, Identity Server, Identity Server as Key Manager, Open Banking AM, Open Banking IAM, Traffic Manager and Universal Gateway. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Conditional Authentication. Executing a manipulation can lead to improper authorization.

This vulnerability appears as CVE-2025-15039. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More