{"id":"CVE-2026-3418","title":"Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution","summary":"The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated ad…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-434"],"vendor":"WSO2","product":"WSO2 API Manager","affected":["api_manager >= 4.4.0 < 4.4.0.67","api_manager >= 4.5.0 < 4.5.0.52","api_manager >= 4.6.0 < 4.6.0.16","traffic_manager >= 4.5.0 < 4.5.0.51","traffic_manager >= 4.6.0 < 4.6.0.16","api_control_plane >= 4.5.0 < 4.5.0.53","api_control_plane >= 4.6.0 < 4.6.0.17","universal_gateway >= 4.5.0 < 4.5.0.52","universal_gateway >= 4.6.0 < 4.6.0.16","org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.30.67 < 9.30.67.156","org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.31.86 < 9.31.86.141","org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.32.147 < 9.32.147.44","org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.30.67 < 9.30.67.156","org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.31.86 < 9.31.86.141","org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.32.147 < 9.32.147.44","org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api >= 9.30.67 < 9.30.67.156"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-07T17:46:58.452271Z"},"published":"2026-08-06","updated":"2026-09-23","sourceUpdated":"2026-09-23T15:30:30.610Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-3418","references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/"}],"tags":["cve.org"],"epss":0.00573,"epssPercentile":0.46109,"ingestedAt":"2026-09-23T16:27:22.665Z","slug":"CVE-2026-3418","body":"## Overview\n\nThe System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges.\n\nSuccessful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.\n\n## Affected\n\n- `api_manager >= 4.4.0 < 4.4.0.67`\n- `api_manager >= 4.5.0 < 4.5.0.52`\n- `api_manager >= 4.6.0 < 4.6.0.16`\n- `traffic_manager >= 4.5.0 < 4.5.0.51`\n- `traffic_manager >= 4.6.0 < 4.6.0.16`\n- `api_control_plane >= 4.5.0 < 4.5.0.53`\n- `api_control_plane >= 4.6.0 < 4.6.0.17`\n- `universal_gateway >= 4.5.0 < 4.5.0.52`\n- `universal_gateway >= 4.6.0 < 4.6.0.16`\n- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.30.67 < 9.30.67.156`\n- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.31.86 < 9.31.86.141`\n- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.32.147 < 9.32.147.44`\n- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.30.67 < 9.30.67.156`\n- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.31.86 < 9.31.86.141`\n- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.32.147 < 9.32.147.44`\n- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api >= 9.30.67 < 9.30.67.156`\n\n## Remediation\n\nFollow the instructions given on  https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}