CVE-2026-3418 Details
Description
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.
A vulnerability exists in multiple WSO2 products, including WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, all versions 4.6.0 and 4.5.0. The issue arises because the System REST API allows file uploads without adequate validation of file types or destinations. This flaw enables authenticated users with administrative rights and publisher privileges to upload files to arbitrary locations on the server. Depending on the environment and how the uploaded files are managed, this could result in the execution of the uploaded content, potentially leading to remote code execution.
WSO2 community users should apply the public fix available on GitHub or migrate to the latest unaffected version of the respective WSO2 product. WSO2 support subscription holders can update to the specified update level or use WSO2 Updates to apply the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/ | WSO2 LLC | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| WSO2 API Control Plane | 4.6.0 (semver) 4.5.0 (semver) |
CPE
Remediation
| |
| WSO2 API Manager | 4.6.0 (semver) 4.5.0 (semver) 4.4.0 (semver) |
CPE
Remediation
| |
| WSO2 Traffic Manager | 4.6.0 (semver) 4.5.0 (semver) |
CPE
Remediation
| |
| WSO2 Universal Gateway | 4.6.0 (semver) 4.5.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | WSO2 LLC |
Volerion