---
id: CVE-2025-13426
title: >-
  A vulnerability exists in Google  Apigee's JavaCallout policy
  https://docs.apigee.com/api-platform/reference/policies/java-callout-policy 
  that allows for remote code execution.


  It is possible for a user to write a JavaCallout that inje…
summary: >-
  A vulnerability exists in Google  Apigee's JavaCallout policy
  https://docs.apigee.com/api-platform/reference/policies/java-callout-policy 
  that allows for remote code execution.


  It is possible for a user to write a JavaCallout that inje…
severity: none
cwe:
  - CWE-913
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13426'
references:
  - url: >-
      https://docs.cloud.google.com/apigee/docs/hybrid/release-notes#March_01_2025
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
tags:
  - nvd
epss: 0.0042
epssPercentile: 0.33725
ingestedAt: '2026-09-25T23:21:16.900Z'
---

## Overview

A vulnerability exists in Google  Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/java-callout-policy  that allows for remote code execution.

It is possible for a user to write a JavaCallout that injected a malicious object into the MessageContext to execute arbitrary Java code and system commands at runtime, leading to unauthorized access to data, lateral movement within the network, and access to backend systems.

The Apigee hybrid versions below have all been updated to protect from this vulnerability:
  *  Hybrid_1.11.2+
  *  Hybrid_1.12.4+
  *  Hybrid_1.13.3+
  *  Hybrid_1.14.1+
  *  OPDK_5202+
  *  OPDK_5300+

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
