# CVE-2025-12737

## Summary

- **CVE ID:** CVE-2025-12737
- **Severity:** HIGH
- **CVSS Score:** 8.4 (CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-78
- **Published:** Sep 3, 2026
- **Last Modified:** Sep 3, 2026

## Description

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely.

Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.

## Affected Products

- WSO2 — WSO2 Open Banking AM (0)
- WSO2 — WSO2 Open Banking AM (2.0.0)
- WSO2 — WSO2 Open Banking IAM (0)
- WSO2 — WSO2 Open Banking IAM (2.0.0)
- WSO2 — WSO2 Traffic Manager (4.5.0)
- WSO2 — WSO2 Traffic Manager (4.6.0)
- WSO2 — WSO2 Universal Gateway (4.5.0)
- WSO2 — WSO2 Universal Gateway (4.6.0)
- WSO2 — WSO2 API Control Plane (4.5.0)
- WSO2 — WSO2 API Control Plane (4.6.0)
- WSO2 — WSO2 API Manager (0)
- WSO2 — WSO2 API Manager (3.1.0)
- WSO2 — WSO2 API Manager (3.2.0)
- WSO2 — WSO2 API Manager (3.2.1)
- WSO2 — WSO2 API Manager (4.0.0)
- WSO2 — WSO2 API Manager (4.1.0)
- WSO2 — WSO2 API Manager (4.2.0)
- WSO2 — WSO2 API Manager (4.3.0)
- WSO2 — WSO2 API Manager (4.4.0)
- WSO2 — WSO2 API Manager (4.5.0)
- WSO2 — WSO2 API Manager (4.6.0)
- WSO2 — WSO2 Identity Server as Key Manager (0)
- WSO2 — WSO2 Identity Server as Key Manager (5.10.0)
- WSO2 — WSO2 Identity Server (0)
- WSO2 — WSO2 Identity Server (5.10.0)
- WSO2 — WSO2 Identity Server (5.11.0)
- WSO2 — WSO2 Identity Server (6.0.0)
- WSO2 — WSO2 Identity Server (6.1.0)
- WSO2 — WSO2 Identity Server (7.0.0)
- WSO2 — WSO2 Identity Server (7.1.0)
- WSO2 — WSO2 Identity Server (7.2.0)

## References

- [CNA](https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4771/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 13.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._