CVE-2025-13394Medium· 5.4▾ SunlitThe Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions.
An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.
api_control_plane >= 4.5.0, < 4.5.0.39api_control_plane >= 4.6.0, < 4.6.0.3api_manager >= 3.1.0, < 3.1.0.352api_manager >= 3.2.0, < 3.2.0.456api_manager >= 3.2.1, < 3.2.1.75api_manager >= 4.0.0, < 4.0.0.376api_manager >= 4.1.0, < 4.1.0.239api_manager >= 4.2.0, < 4.2.0.179api_manager >= 4.3.0, < 4.3.0.91api_manager >= 4.4.0, < 4.4.0.55api_manager >= 4.5.0, < 4.5.0.38api_manager >= 4.6.0, < 4.6.0.3enterprise_integrator >= 6.6.0, < 6.6.0.227identity_server >= 5.10.0, < 5.10.0.381identity_server >= 5.11.0, < 5.11.0.428identity_server >= 6.0.0, < 6.0.0.255identity_server >= 6.1.0, < 6.1.0.256identity_server >= 7.0.0, < 7.0.0.133identity_server >= 7.1.0, < 7.1.0.41identity_server >= 7.2.0, < 7.2.0.3identity_server_as_key_manager >= 5.10.0, < 5.10.0.372open_banking_am >= 2.0.0, < 2.0.0.401open_banking_iam >= 2.0.0, < 2.0.0.421traffic_manager >= 4.5.0, < 4.5.0.37traffic_manager >= 4.6.0, < 4.6.0.3universal_gateway >= 4.5.0, < 4.5.0.37universal_gateway >= 4.6.0, < 4.6.0.3Upgrade past the affected range:
api_control_plane 4.6.0.3api_manager 4.6.0.3enterprise_integrator 6.6.0.227identity_server 7.2.0.3identity_server_as_key_manager 5.10.0.372open_banking_am 2.0.0.401open_banking_iam 2.0.0.421traffic_manager 4.6.0.3universal_gateway 4.6.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15039Critical· 9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured
CVE-2025-9804Critical· 9.6An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs
CVE-2026-5430Critical· 10.0The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported
CVE-2026-3416Medium· 5.9The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation
CVE-2025-12737High· 8.4The administrative operations within the Carbon Console do not adequately validate specific user-supplied input
CVE-2024-6832Medium· 5.9The account locking mechanism fails to trigger when secondary user stores are inaccessible