Description
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely.

Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
Published: 2026-09-03
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The flaw lies in insufficient validation of user-supplied input during certain administrative operations in the Carbon Console. An administrator who can invoke these actions can inject code that is executed on the host, leading to a full compromise of the affected system. This vulnerability is categorized as CWE‑78 and allows the execution of arbitrary code.

Affected Systems

The vulnerability affects several WSO2 products: WSO2 API Control Plane, WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, WSO2 Traffic Manager, and WSO2 Universal Gateway. An explicit list of affected product versions is not provided in the advisory.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. The exploit requires an attacker to have administrative privileges and access to the Carbon Console; it is carried out remotely through the administrative interface. Once leveraged, the attacker can execute arbitrary code on the host system.

Generated by OpenCVE AI on September 3, 2026 at 14:48 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4771/#solution


OpenCVE Recommended Actions

  • Apply the latest security update for the affected WSO2 product as described in the vendor's advisory.
  • Restrict Carbon Console access to trusted administrators and limit its exposure to internal networks only.
  • Enforce strict input validation or environment isolation to prevent injection of malicious commands.

Generated by OpenCVE AI on September 3, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wso2:api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_control_plane:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:api_manager:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:identity_server_as_key_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_am:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:open_banking_iam:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:traffic_manager:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:wso2:universal_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:universal_gateway:4.6.0:*:*:*:*:*:*:*

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 api Control Plane
Wso2 api Manager
Wso2 identity Server
Wso2 identity Server As Key Manager
Wso2 open Banking Am
Wso2 open Banking Iam
Wso2 traffic Manager
Wso2 universal Gateway
Vendors & Products Wso2 api Control Plane
Wso2 api Manager
Wso2 identity Server
Wso2 identity Server As Key Manager
Wso2 open Banking Am
Wso2 open Banking Iam
Wso2 traffic Manager
Wso2 universal Gateway

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
Title Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution
First Time appeared Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam
Wso2 wso2 Traffic Manager
Wso2 wso2 Universal Gateway
Weaknesses CWE-78
CPEs cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_identity_server_as_key_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_open_banking_am:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_open_banking_iam:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Wso2 wso2 Identity Server
Wso2 wso2 Identity Server As Key Manager
Wso2 wso2 Open Banking Am
Wso2 wso2 Open Banking Iam
Wso2 wso2 Traffic Manager
Wso2 wso2 Universal Gateway
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Wso2 Api Control Plane Api Manager Identity Server Identity Server As Key Manager Open Banking Am Open Banking Iam Traffic Manager Universal Gateway Wso2 Api Control Plane Wso2 Api Manager Wso2 Identity Server Wso2 Identity Server As Key Manager Wso2 Open Banking Am Wso2 Open Banking Iam Wso2 Traffic Manager Wso2 Universal Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-09-03T13:34:31.346Z

Reserved: 2025-11-05T03:08:36.082Z

Link: CVE-2025-12737

cve-icon Vulnrichment

Updated: 2026-09-03T13:34:28.139Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-03T14:17:00.183

Modified: 2026-09-09T20:00:20.833

Link: CVE-2025-12737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')