CVE-2025-12737

Published Sep 3, 2026

Last updated 11 days ago

Overview

Description
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD status
Analyzed
Products
api_control_plane, api_manager, identity_server, identity_server_as_key_manager, open_banking_am, open_banking_iam, traffic_manager, universal_gateway

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.4
Impact score
6
Exploitability score
1.7
Vector string
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

ed10eef1-636d-4fbe-9993-6890dfa878f8
CWE-78

Social media

Hype score
Not currently trending

Configurations