CVE-2025-12737High· 8.4▾ TwilightThe administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Succe…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely.
Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
api_control_plane >= 4.5.0, < 4.5.0.36api_control_plane = 4.6.0api_manager >= 3.1.0, < 3.1.0.349api_manager >= 3.2.0, < 3.2.0.453api_manager >= 3.2.1, < 3.2.1.73api_manager >= 4.0.0, < 4.0.0.373api_manager >= 4.1.0, < 4.1.0.236api_manager >= 4.2.0, < 4.2.0.176api_manager >= 4.3.0, < 4.3.0.88api_manager >= 4.4.0, < 4.4.0.52api_manager >= 4.5.0, < 4.5.0.35api_manager = 4.6.0identity_server >= 5.10.0, < 5.10.0.378identity_server >= 5.11.0, < 5.11.0.425identity_server >= 6.0.0, < 6.0.0.252identity_server >= 6.1.0, < 6.1.0.253identity_server >= 7.0.0, < 7.0.0.130identity_server >= 7.1.0, < 7.1.0.38identity_server = 7.2.0identity_server_as_key_manager >= 5.10.0, < 5.10.0.369open_banking_am >= 2.0.0, < 2.0.0.398open_banking_iam >= 2.0.0, < 2.0.0.418traffic_manager >= 4.5.0, < 4.5.0.34traffic_manager = 4.6.0universal_gateway >= 4.5.0, < 4.5.0.34universal_gateway = 4.6.0Upgrade past the affected range:
api_control_plane 4.5.0.36api_manager 4.5.0.35identity_server 7.1.0.38identity_server_as_key_manager 5.10.0.369open_banking_am 2.0.0.398open_banking_iam 2.0.0.418traffic_manager 4.5.0.34universal_gateway 4.5.0.34Connected by shared product, vendor, weakness, or advisory.
CVE-2026-3416Medium· 5.9The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation
CVE-2026-19515High· 7.0The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources
CVE-2024-6832Medium· 5.9The account locking mechanism fails to trigger when secondary user stores are inaccessible
CVE-2024-10302Medium· 4.0The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CVE-2020-3167High· 7.8A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS)