CRITICAL🇵🇱 Wersja polska

CVE-2025-13590

CVSS 9.1v3.1pub. 2026-02-19upd. 2026-06-18

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

🤖 AI Analysis
How it works

An attacker with administrator privileges can use the system REST API to upload a specially crafted file (payload) to a selected location in the deployment environment. The lack of proper validation of uploaded files (CWE-434 – Unrestricted Upload of File with Dangerous Type) allows placement of malicious code on the server side. Subsequently, execution of such a file by the server leads to system takeover.

Impact

An attacker can gain the ability to execute arbitrary code remotely on the server (RCE), which in practice means complete takeover of the system, potential access to sensitive data, and the possibility of further lateral movement within the organization's network.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references – detailed instructions are contained in the WSO2-2025-4849 advisory available at https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4849/. Until the update is applied, it is recommended to restrict access to the system REST API only to trusted, authorized entities and strengthen controls over administrative accounts.

Who is affected

WSO2 API Control Plane and WSO2 API Manager – versions indicated in the vendor's references (details in security advisory WSO2-2025-4849)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wso2 Api Control Plane

    APP
    Wso2
    4.5.04.6.0
  • Wso2 Api Manager

    APP
    Wso2
    4.2.04.3.04.4.04.5.04.6.0
  • Wso2 Traffic Manager

    APP
    Wso2
    4.5.04.6.0
  • Wso2 Universal Gateway

    APP
    Wso2
    4.5.04.6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2022-29464CRITICAL9.8⚠ KEVPL ✓same product

WSO2 — nieograniczony upload plików i RCE przez path traversal

CVE-2026-1728CRITICAL9.8PL ✓same product

WSO2: niedostateczne ograniczenia tokenów użytkowników — dostęp do Admin REST API

CVE-2026-5430CRITICAL10.0PL ✓same product

Błąd weryfikacji algorytmu JWT umożliwia nieautoryzowany dostęp (WSO2)

CVE-2025-15039CRITICAL9.4PL ✓same product

Pominięcie uwierzytelniania wieloetapowego w WSO2 Conditional Authentication

CVE-2025-9312CRITICAL9.8PL ✓same product

Brak wymuszania uwierzytelniania mTLS w produktach WSO2 — nieautoryzowany dostęp administracyjny