CVE-2026-3418
Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.
| CWE | CWE-434 |
| Vendor | wso2 |
| Product | wso2 api manager |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for wso2 wso2 api manager
Be the first to know when new critical vulnerabilities affecting wso2 wso2 api manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
WSO2 / WSO2 API Manager
4.4.0 < 4.4.0.67 4.5.0 < 4.5.0.52 4.6.0 < 4.6.0.16
WSO2 / WSO2 Traffic Manager
4.5.0 < 4.5.0.51 4.6.0 < 4.6.0.16
WSO2 / WSO2 API Control Plane
4.5.0 < 4.5.0.53 4.6.0 < 4.6.0.17
WSO2 / WSO2 Universal Gateway
4.5.0 < 4.5.0.52 4.6.0 < 4.6.0.16
WSO2 / WSO2 Carbon API Management Implementation
9.30.67 < 9.30.67.156 9.31.86 < 9.31.86.141 9.32.147 < 9.32.147.44
WSO2 / WSO2 API Manager Publisher REST API V4
9.30.67 < 9.30.67.156 9.31.86 < 9.31.86.141 9.32.147 < 9.32.147.44
WSO2 / WSO2 Carbon API Management API
9.30.67 < 9.30.67.156