A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
An attacker with administrator privileges can use the system REST API to upload a specially crafted file (payload) to a selected location in the deployment environment. The lack of proper validation of uploaded files (CWE-434 – Unrestricted Upload of File with Dangerous Type) allows placement of malicious code on the server side. Subsequently, execution of such a file by the server leads to system takeover.
An attacker can gain the ability to execute arbitrary code remotely on the server (RCE), which in practice means complete takeover of the system, potential access to sensitive data, and the possibility of further lateral movement within the organization's network.
Patches available from the vendor should be applied in accordance with the references – detailed instructions are contained in the WSO2-2025-4849 advisory available at https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4849/. Until the update is applied, it is recommended to restrict access to the system REST API only to trusted, authorized entities and strengthen controls over administrative accounts.
WSO2 API Control Plane and WSO2 API Manager – versions indicated in the vendor's references (details in security advisory WSO2-2025-4849)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWso2 Api Control Plane
APPWso24.5.04.6.0Wso2 Api Manager
APPWso24.2.04.3.04.4.04.5.04.6.0Wso2 Traffic Manager
APPWso24.5.04.6.0Wso2 Universal Gateway
APPWso24.5.04.6.0
Related vulnerabilities
WSO2 — nieograniczony upload plików i RCE przez path traversal
WSO2: niedostateczne ograniczenia tokenów użytkowników — dostęp do Admin REST API
Błąd weryfikacji algorytmu JWT umożliwia nieautoryzowany dostęp (WSO2)
Pominięcie uwierzytelniania wieloetapowego w WSO2 Conditional Authentication
Brak wymuszania uwierzytelniania mTLS w produktach WSO2 — nieautoryzowany dostęp administracyjny