Remote Code Execution Vulnerability in Carbon Console by WSO2
CVE-2025-12737
8.4HIGH
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 3 September 2026
What is CVE-2025-12737?
A vulnerability exists within the Carbon Console due to inadequate input validation in administrative operations. This flaw enables an attacker with existing administrative privileges to inject and execute arbitrary code remotely. The exploitation of this vulnerability allows complete compromise of the system, emphasizing the importance of strict input validation mechanisms in safeguarding against such security threats.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.36
WSO2 API Control Plane 4.6.0 < 4.6.0.1
WSO2 API Manager 3.1.0 < 3.1.0.349
