CVE-2025-12737
Received Received - Intake

Remote Code Execution in Carbon Console

Vulnerability report for CVE-2025-12737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: WSO2 LLC

Description

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
carbon console *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an arbitrary remote code execution flaw in the Carbon Console of WSO2 products. It occurs because administrative operations do not properly validate user-supplied input, allowing an authenticated admin with console access to inject and execute malicious code remotely.

Impact Analysis

If exploited, this vulnerability allows a threat actor with admin privileges to fully compromise the affected system. This could lead to unauthorized access, data theft, system manipulation, or disruption of services.

Mitigation Strategies

Apply public patches from the provided GitHub link or upgrade to the latest unaffected versions of affected WSO2 products. For WSO2 Support Subscription holders, update to specified patch levels or higher.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-12737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart