---
id: CVE-2025-12737
title: >-
  The administrative operations within the Carbon Console do not adequately
  validate specific user-supplied input
summary: >-
  The administrative operations within the Carbon Console do not adequately
  validate specific user-supplied input. This oversight allows a malicious actor
  with administrative privileges to inject and execute arbitrary code remotely.


  Succe…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: wso2
product: api_control_plane
affected:
  - 'api_control_plane >= 4.5.0, < 4.5.0.36'
  - api_control_plane = 4.6.0
  - 'api_manager >= 3.1.0, < 3.1.0.349'
  - 'api_manager >= 3.2.0, < 3.2.0.453'
  - 'api_manager >= 3.2.1, < 3.2.1.73'
  - 'api_manager >= 4.0.0, < 4.0.0.373'
  - 'api_manager >= 4.1.0, < 4.1.0.236'
  - 'api_manager >= 4.2.0, < 4.2.0.176'
  - 'api_manager >= 4.3.0, < 4.3.0.88'
  - 'api_manager >= 4.4.0, < 4.4.0.52'
  - 'api_manager >= 4.5.0, < 4.5.0.35'
  - api_manager = 4.6.0
  - 'identity_server >= 5.10.0, < 5.10.0.378'
  - 'identity_server >= 5.11.0, < 5.11.0.425'
  - 'identity_server >= 6.0.0, < 6.0.0.252'
  - 'identity_server >= 6.1.0, < 6.1.0.253'
  - 'identity_server >= 7.0.0, < 7.0.0.130'
  - 'identity_server >= 7.1.0, < 7.1.0.38'
  - identity_server = 7.2.0
  - 'identity_server_as_key_manager >= 5.10.0, < 5.10.0.369'
  - 'open_banking_am >= 2.0.0, < 2.0.0.398'
  - 'open_banking_iam >= 2.0.0, < 2.0.0.418'
  - 'traffic_manager >= 4.5.0, < 4.5.0.34'
  - traffic_manager = 4.6.0
  - 'universal_gateway >= 4.5.0, < 4.5.0.34'
  - universal_gateway = 4.6.0
patched:
  - api_control_plane 4.5.0.36
  - api_manager 4.5.0.35
  - identity_server 7.1.0.38
  - identity_server_as_key_manager 5.10.0.369
  - open_banking_am 2.0.0.398
  - open_banking_iam 2.0.0.418
  - traffic_manager 4.5.0.34
  - universal_gateway 4.5.0.34
published: '2026-09-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:00:20.833'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12737'
references:
  - url: >-
      https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4771/
    label: ed10eef1-636d-4fbe-9993-6890dfa878f8
tags:
  - nvd
epss: 0.00223
epssPercentile: 0.11521
ingestedAt: '2026-09-09T20:21:14.799Z'
---

## Overview

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely.

Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.

## Affected

- `api_control_plane >= 4.5.0, < 4.5.0.36`
- `api_control_plane = 4.6.0`
- `api_manager >= 3.1.0, < 3.1.0.349`
- `api_manager >= 3.2.0, < 3.2.0.453`
- `api_manager >= 3.2.1, < 3.2.1.73`
- `api_manager >= 4.0.0, < 4.0.0.373`
- `api_manager >= 4.1.0, < 4.1.0.236`
- `api_manager >= 4.2.0, < 4.2.0.176`
- `api_manager >= 4.3.0, < 4.3.0.88`
- `api_manager >= 4.4.0, < 4.4.0.52`
- `api_manager >= 4.5.0, < 4.5.0.35`
- `api_manager = 4.6.0`
- `identity_server >= 5.10.0, < 5.10.0.378`
- `identity_server >= 5.11.0, < 5.11.0.425`
- `identity_server >= 6.0.0, < 6.0.0.252`
- `identity_server >= 6.1.0, < 6.1.0.253`
- `identity_server >= 7.0.0, < 7.0.0.130`
- `identity_server >= 7.1.0, < 7.1.0.38`
- `identity_server = 7.2.0`
- `identity_server_as_key_manager >= 5.10.0, < 5.10.0.369`
- `open_banking_am >= 2.0.0, < 2.0.0.398`
- `open_banking_iam >= 2.0.0, < 2.0.0.418`
- `traffic_manager >= 4.5.0, < 4.5.0.34`
- `traffic_manager = 4.6.0`
- `universal_gateway >= 4.5.0, < 4.5.0.34`
- `universal_gateway = 4.6.0`

## Remediation

Upgrade past the affected range:

- `api_control_plane 4.5.0.36`
- `api_manager 4.5.0.35`
- `identity_server 7.1.0.38`
- `identity_server_as_key_manager 5.10.0.369`
- `open_banking_am 2.0.0.398`
- `open_banking_iam 2.0.0.418`
- `traffic_manager 4.5.0.34`
- `universal_gateway 4.5.0.34`
