CVE-2025-12737
CVE-2025-12737
8.4
HighPublished:
Last updated:
Source:ed10eef1-636d-4fbe-9993-6890dfa878f8
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Adjacent
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
References
ed10eef1-636d-4fbe-9993-6890dfa878f8
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4771/