File Upload Vulnerability in WSO2 API
CVE-2026-3418
9.1CRITICAL
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2026-3418?
A vulnerability exists in the WSO2 API Manager's System REST API that allows authenticated publishers to upload files without sufficient validation. This lack of validation permits arbitrary file uploads to sensitive server locations, which can lead to the execution of malicious content. Exploitation of this vulnerability is contingent upon the attacker having authenticated access with publisher privileges, and if exploited, it could potentially enable remote code execution depending on the specific environment and file handling mechanisms in place.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.53
WSO2 API Control Plane 4.6.0 < 4.6.0.17
WSO2 API Manager 4.4.0 < 4.4.0.67
