8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Clear
Description
A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/java-callout-policy that allows for remote code execution.
It is possible for a user to write a JavaCallout that injected a malicious object into the MessageContext to execute arbitrary Java code and system commands at runtime,Β leading to unauthorized access to data, lateral movement within the network, and access to backend systems.
The Apigee hybrid versions below have all been updated to protect from this vulnerability:
* Hybrid_1.11.2+
* Hybrid_1.12.4+
* Hybrid_1.13.3+
* Hybrid_1.14.1+
* OPDK_5202+
* OPDK_5300+
It is possible for a user to write a JavaCallout that injected a malicious object into the MessageContext to execute arbitrary Java code and system commands at runtime,Β leading to unauthorized access to data, lateral movement within the network, and access to backend systems.
The Apigee hybrid versions below have all been updated to protect from this vulnerability:
* Hybrid_1.11.2+
* Hybrid_1.12.4+
* Hybrid_1.13.3+
* Hybrid_1.14.1+
* OPDK_5202+
* OPDK_5300+
AI Analysis
Remote code execution vulnerability in Google Apigee's JavaCallout policy due to improper sandboxing, allowing unauthorized access to data and systems.
Basic Information
ID
CVE-2025-13426
Source
GoogleCloud
Published
Dec 5, 2025 at 21:27
Modified
Dec 5, 2025 at 21:46
Affected Product
Vendor
Google Cloud
Product
Apigee hybrid Javacallout policy
Affected Versions
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
Google Cloud Apigee hybrid Javacallout policy 0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Google Cloud
Product
Apigee hybrid Javacallout policy
Version
Hybrid_1.11.2+, Hybrid_1.12.4+, Hybrid_1.13.3+, Hybrid_1.14.1+, OPDK_5202+, OPDK_5300+