The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2025-15039 is a critical authentication bypass vulnerability (CVSS 9.4) affecting conditional authentication systems that implement adaptive or multi-step authentication workflows. The vulnerability exists in how authentication scripts handle callback mechanisms and step re-execution when multiple authenticators are configured in a specific pattern. Rather than enforcing completion of all required authentication steps sequentially, the flawed logic allows attackers to skip intermediate challenges, granting unauthorized account access. This impacts any organization using affected conditional authentication platforms, particularly those relying on multi-factor authentication (MFA) as a primary security control. The vulnerability is especially dangerous because it undermines the trust in adaptive authentication systems designed to protect high-value accounts and sensitive operations.
While CVE-2025-15039 currently maps to zero Casky skills due to its emerging nature, practitioners using Casky.ai can leverage Claude's extended reasoning capabilities to model attack patterns related to authentication bypass techniques. Security teams should focus on behavior-based detection patterns that identify: (1) authentication session anomalies where users skip expected MFA challenges, (2) callback/re-execution sequences that deviate from configured authentication flows, and (3) rapid authentication state transitions that bypass intermediate steps. By analyzing authentication logs through Casky's skill framework, practitioners can identify suspicious patterns in how conditional authentication scripts are being invoked and whether all required steps are genuinely completing. As this vulnerability matures and additional skills are mapped, organizations should prioritize patching conditional authentication systems and implementing detection rules that validate the sequential completion of all configured authentication factors.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2025-15039. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation