CVE-2025-15039
Auth bypass in Conditional/Adaptive Authentication script enabling account takeover.
Is CVE-2025-15039 being exploited?
Not confirmed. CVE-2025-15039 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.40% probability of exploitation in the next 30 days.
How severe is CVE-2025-15039?
CVE-2025-15039 is rated Critical with a CVSS score of 9.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2025-15039?
Yes. A fix has been recorded for CVE-2025-15039. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2025-15039 affect?
CVE-2025-15039 affects Conditional/Adaptive Authentication scripts, Identity providers using custom adaptive auth, Accounts with enrolled secondary authenticators. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2025-15039?
Disable or revert conditional auth scripts; enforce full auth steps, rotate creds, audit logs; apply vendor patch when released.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Authentication bypass that skips intermediate MFA/secondary authenticators, allowing unauthorized account access (account takeover).
Immediate action required
- affected>= 4.5.0 and < 4.5.0.45
- affected>= 4.6.0 and < 4.6.0.9
- affected< 2.6.0
- affected>= 2.6.0 and < 2.6.0.150
- affected>= 3.0.0 and < 3.0.0.180
- affected>= 3.1.0 and < 3.1.0.356
- affected>= 3.2.0 and < 3.2.0.460
- affected>= 3.2.1 and < 3.2.1.79
- affected>= 4.0.0 and < 4.0.0.381
- affected>= 4.1.0 and < 4.1.0.244
- affected>= 4.2.0 and < 4.2.0.184
- affected>= 4.3.0 and < 4.3.0.95
- affected>= 4.4.0 and < 4.4.0.59
- affected>= 4.5.0 and < 4.5.0.44
- affected>= 4.6.0 and < 4.6.0.8
- affected>= 5.12.153 and < 5.12.153.66
- affected>= 5.12.387 and < 5.12.387.48
- affected>= 5.14.97 and < 5.14.97.94
- affected>= 5.17.5 and < 5.17.5.337
- affected>= 5.17.118 and < 5.17.118.24
- affected>= 5.18.187 and < 5.18.187.334
- affected>= 5.18.248 and < 5.18.248.34
- affected>= 5.23.8 and < 5.23.8.221
- affected>= 5.24.8 and < 5.24.8.29
- affected>= 5.25.92 and < 5.25.92.177
- affected>= 5.25.705 and < 5.25.705.23
- affected>= 5.25.713 and < 5.25.713.12
- affected>= 5.25.724 and < 5.25.724.8
- affected>= 5.25.736 and < 5.25.736.3
- affected>= 7.0.78 and < 7.0.78.171
- affected>= 7.8.23 and < 7.8.23.95
- affected>= 7.8.586 and < 7.8.586.21
- affected< 5.7.0
- affected>= 5.7.0 and < 5.7.0.130
- affected>= 5.8.0 and < 5.8.0.113
- affected>= 5.9.0 and < 5.9.0.173
- affected>= 5.10.0 and < 5.10.0.385
- affected>= 5.11.0 and < 5.11.0.432
- affected>= 6.0.0 and < 6.0.0.259
- affected>= 6.1.0 and < 6.1.0.260
- affected>= 7.0.0 and < 7.0.0.138
- affected>= 7.1.0 and < 7.1.0.45
- affected>= 7.1.0 and < 7.1.0.49
- affected>= 7.2.0 and < 7.2.0.7
- affected< 5.7.0
- affected>= 5.7.0 and < 5.7.0.129
- affected>= 5.9.0 and < 5.9.0.179
- affected>= 5.10.0 and < 5.10.0.376
- affected< 1.4.0
- affected>= 1.4.0 and < 1.4.0.143
- affected>= 1.5.0 and < 1.5.0.144
- affected>= 2.0.0 and < 2.0.0.405
- affected< 2.0.0
- affected>= 2.0.0 and < 2.0.0.425
- affected< 1.4.0
- affected>= 1.4.0 and < 1.4.0.137
- affected>= 1.5.0 and < 1.5.0.127
- affected< 4.5.0
- affected>= 4.5.0 and < 4.5.0.43
- affected>= 4.6.0 and < 4.6.0.8
- affected>= 4.5.0 and < 4.5.0.43
- affected>= 4.5.0 and < 4.5.0.44
- affected>= 4.6.0 and < 4.6.0.8
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.