CVE-2025-12107Disclosure(wso2 / identity_server)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wso2 identity_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax. Successful exploitation enables an attacker with administrative privileges to execute arbitrary template code on the server. This can lead to significant security consequences, including remote code execution, manipulation of data, and unauthorized access to sensitive information.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
identity_server

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-19: 2Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 102-1902-20
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure2
2026-02-201
Patch1
Full discourse3 posts
  • CCB Alert@CCBalert
    Patch

    Warning: #RCE vulnerabilities in #WSO2 API Manager and Identity Server. #CVE-2025-13590 (CVSS 9.1) allows arbitrary file upload in API Manager, while #CVE-2025-12107 (CVSS 8.4) enables template injection in Identity Server. #Patch #Patch #Patch More info: https://security.docs.wso2.com/en/latest/security-announcements/

    Post summary

    WSO2 issues a warning about two high‑severity CVEs affecting its API Manager and Identity Server, detailing the vulnerabilities and providing a patch via its security documentation.

    01032334
    7.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-12107 - Critical Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. ... https://www.thehackerwire.com/vulnerability/CVE-2025-12107/ https://t.co/L0cVww3VAN

    Post summary

    The text announces a critical vulnerability (CVE‑2025‑12107) involving the Velocity template engine, describing how malicious actors with admin privileges can inject and execute arbitrary template syntax, but it does not provide PoC, exploit code, or patch details.

    0000033
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-12107** pertains to a critical security flaw in the use of a third-party Velocity template engine within a server environment. The vulnerability arises because the Velocity engine, which is responsible for rendering server-side templates, contains a security flaw that allows an attacker with administrative privileges to inject malicious template syntax. This injection can lead to arbitrary code execution on the server. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation #DDoS https://cvetodo.com/cve/CVE-2025-12107

    Post summary

    The post announces CVE-2025-12107 as a critical flaw in the Velocity template engine that permits admin users to inject template syntax and achieve arbitrary code execution; it provides technical detail but no PoC, exploit, patch, or active exploitation claims.

    0000030
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2identity_server5.11.0--

Explore more