PT-2026-68724 · Wso2 · Wso2 Api Control Plane+6

CVE-2026-3418

·

Published

2026-08-06

·

Updated

2026-08-31

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The System REST API fails to properly validate file types or destinations during user-supplied file uploads. This allows an authenticated user with administrative publisher privileges to write files to arbitrary server-accessible locations. Depending on the environment and file handling, this could lead to the execution of the uploaded content, potentially resulting in remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3418

Affected Products

Wso2 Api Control Plane
Wso2 Api Manager
Wso2 Api Manager Publisher Rest Api V4
Wso2 Carbon Api Management Api
Wso2 Carbon Api Management Implementation
Wso2 Traffic Manager
Wso2 Universal Gateway