Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and execute arbitrary template code on the server, potentially leading to remote code execution, data manipulation, or unauthorized access to sensitive information.
Use CWE-1336, Wso2 vendor hub and Identity Server product page to widen CVE-2025-12107 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-9312, CVE-2025-6670 and CVE-2025-10907 for nearby disclosures in the same product family.