The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax.

Successful exploitation enables an attacker with administrative privileges to execute arbitrary template code on the server. This can lead to significant security consequences, including remote code execution, manipulation of data, and unauthorized access to sensitive information.
Advisories

No advisories yet.

Fixes

Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4517/#solution


Workaround

No workaround given by the vendor.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1336

Thu, 03 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information. The Velocity template engine, utilized by the affected product, accepts and processes template syntax without sufficient sanitization or validation of user-controlled input. This allows an authenticated administrator to inject arbitrary template syntax. Successful exploitation enables an attacker with administrative privileges to execute arbitrary template code on the server. This can lead to significant security consequences, including remote code execution, manipulation of data, and unauthorized access to sensitive information.
Title Potential authenticated Server-Side Template Injection (SSTI) vulnerability. Server-Side Template Injection via Velocity Template Engine in Multiple WSO2 Products Allows Remote Code Execution
Weaknesses CWE-77
CWE-94
CPEs cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:*
Vendors & Products Wso2 wso2 Identity Server

Fri, 06 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Fri, 20 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*

Thu, 19 Feb 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Wso2 identity Server
Vendors & Products Wso2 identity Server

Thu, 19 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
Description Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.
Title Potential authenticated Server-Side Template Injection (SSTI) vulnerability.
First Time appeared Wso2
Wso2 wso2 Identity Server
Weaknesses CWE-1336
CPEs cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Identity Server
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-09-03T13:25:20.318Z

Reserved: 2025-10-23T11:28:43.355Z

Link: CVE-2025-12107

cve-icon Vulnrichment

Updated: 2026-02-20T20:41:51.440Z

cve-icon NVD

Status : Modified

Published: 2026-02-19T10:16:09.967

Modified: 2026-09-03T14:17:00.010

Link: CVE-2025-12107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-19T14:37:55Z

Weaknesses