CVE-2025-12737
8.4WSO2 · Open Banking AM
Administrative operations within the WSO2 Carbon Console fail to properly validate input, allowing an attacker with administrative privileges to execute arbitrary OS commands remotely.
Executive summary
A critical OS command injection vulnerability in the WSO2 Carbon Console allows authenticated administrators to achieve full remote code execution and system compromise.
Vulnerability
This vulnerability is an OS Command Injection (CWE-78) flaw residing in the Carbon Console. It requires an attacker to possess existing administrative privileges to successfully trigger the execution of arbitrary commands.
Business impact
Successful exploitation leads to a total compromise of the affected system, as the attacker gains the ability to execute arbitrary code with the privileges of the underlying application service. Given the CVSS score of 8.4, the business impact is severe, potentially resulting in unauthorized data exfiltration, service disruption, and the loss of integrity for critical API management infrastructure.
Remediation
Immediate Action: Administrators must review the official WSO2 security advisory at https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4771/ and apply the provided patches for their specific product version immediately.
Proactive Monitoring: Security teams should monitor system and application logs for unusual process execution patterns or unexpected shell commands originating from the Carbon Console service account.
Compensating Controls: Restrict access to the Carbon Console to trusted management networks only and ensure the principle of least privilege is applied to all accounts with administrative access to the platform.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates a rapid response to ensure that all affected WSO2 components are updated to the vendor-specified patch levels. Organizations should prioritize patching in production environments that expose the Carbon Console to network segments to minimize the risk of lateral movement by an adversary who has gained administrative credentials.