CVE-2025-12107

Published Feb 19, 2026

Last updated 2 months ago

Overview

Description
Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD status
Modified
Products
identity_server

Risk scores

CVSS 3.1

Type
Primary
Base score
7.2
Impact score
5.9
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

ed10eef1-636d-4fbe-9993-6890dfa878f8
CWE-1336

Social media

Hype score
Not currently trending

Configurations