216.73.217.22

CVE-2025-12107

· Published 19/02/2026 10:16 · Modified 19/02/2026 19:56

Labels: CVE-2025-12107 2026-02-19CVE-2025-12107CWE-1336ed10eef1-636d-4fbe-9993-6890dfa878f8

Essential information

Published
19/02/2026 10:16
Modified
19/02/2026 19:56
Author
Creator
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.

NVD status

Status
Analyzed — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD
View on NVD

Affected products (CPE)

ProductCPE
wso2 / identity server cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*

References