CVE Feed

    Dashboard / CVE / CVE-2025-13394

    CVE-2025-13394

    The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions. An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.

    Published:Aug 6, 2026
    Last Modified:Aug 12, 2026
    EPS:Aug 6, 2026
    EPSS Score:0.00114
    CVSS Score:5.4

    Affected Products

    Vendor
    Wso2
    Product
    Api Control Plane
    Vendor
    Wso2
    Product
    Api Manager
    Vendor
    Wso2
    Product
    Enterprise Integrator
    Vendor
    Wso2
    Product
    Identity Server
    Vendor
    Wso2
    Product
    Identity Server As Key Manager
    Vendor
    Wso2
    Product
    Open Banking Am
    Vendor
    Wso2
    Product
    Open Banking Iam
    Vendor
    Wso2
    Product
    Traffic Manager
    Vendor
    Wso2
    Product
    Universal Gateway
    Vendor
    Wso2
    Product
    Wso2 Api Control Plane
    Vendor
    Wso2
    Product
    Wso2 Api Manager
    Vendor
    Wso2
    Product
    Wso2 Carbon Command Mediator Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Component Andes Event Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Component Andes Ui1
    Vendor
    Wso2
    Product
    Wso2 Carbon Email Verification Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Endpoint Editor Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Event Simulator Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Eventing Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Execution Manager Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Governance
    Vendor
    Wso2
    Product
    Wso2 Carbon Governance Custom Lifecycle Checklist Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Governance Generic Artifact User Interface
    Vendor
    Wso2
    Product
    Wso2 Carbon Governance Life Cycles User Interface
    Vendor
    Wso2
    Product
    Wso2 Carbon Governance Wsdl Tool Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Hl7 Business Messaging Store Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Humantask Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Identity Entitlement Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Identity Management Ui1
    Vendor
    Wso2
    Product
    Wso2 Carbon Identity User Store Configuration Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Logging Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon New Data Sources Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Publish Event Mediator Configuration Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Registry Indexing
    Vendor
    Wso2
    Product
    Wso2 Carbon Registry Info Ui2
    Vendor
    Wso2
    Product
    Wso2 Carbon Registry Profiles Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Registry Properties Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Registry Relations Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Registry Resources Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Registry Search Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Rest Api Admin Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Rule Mediator Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Security Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Sequence Editor Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Task Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Tasks Core
    Vendor
    Wso2
    Product
    Wso2 Carbon Template Editor Ui
    Vendor
    Wso2
    Product
    Wso2 Carbon Throttle Mediator Ui
    Vendor
    Wso2
    Product
    Wso2 Enterprise Integrator
    Vendor
    Wso2
    Product
    Wso2 Identity Server
    Vendor
    Wso2
    Product
    Wso2 Identity Server As Key Manager
    Vendor
    Wso2
    Product
    Wso2 Open Banking Am
    Vendor
    Wso2
    Product
    Wso2 Open Banking Iam
    Vendor
    Wso2
    Product
    Wso2 Stratos Sso Redirector Ui Component
    Vendor
    Wso2
    Product
    Wso2 Stratos User Interface For Tenant Crud Operations
    Vendor
    Wso2
    Product
    Wso2 Traffic Manager
    Vendor
    Wso2
    Product
    Wso2 Universal Gateway

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High