Arbitrary File Upload Vulnerability in WSO2 Products
CVE-2025-1862
6.7MEDIUM
Key Information:
- Vendor
Wso2
- Status
- Vendor
- CVE Published:
- 26 September 2025
What is CVE-2025-1862?
A vulnerability has been identified in multiple WSO2 products that stems from inadequate validation of user-supplied filenames within the BPEL uploader SOAP service endpoint. This flaw allows an attacker with administrative permissions to upload arbitrary files to a user-controlled directory on the server. By exploiting this vulnerability, a malicious user could upload a specially crafted payload, which may lead to remote code execution (RCE). If successfully executed, this could result in full system compromise and unauthorized access to sensitive data.
Affected Version(s)
WSO2 Enterprise Integrator 6.6.0 < 6.6.0.215
WSO2 Identity Server 5.10.0 < 5.10.0.347
WSO2 Identity Server 5.11.0 < 5.11.0.396