---
id: CVE-2025-13590
title: >-
  Authenticated arbitrary file upload via a System REST API requiring
  administrator permission.
summary: >-
  A malicious actor with administrative privileges can upload an arbitrary file
  to a user-controlled location within the deployment via a system REST API.
  Successful uploads may lead to remote code execution. 

   By leveraging the vulnerabi…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cvssSource: cna
vendor: WSO2
product: WSO2 API Manager
affected:
  - api_manager >= 4.2.0 < 4.2.0.179
  - api_manager >= 4.3.0 < 4.3.0.91
  - api_manager >= 4.4.0 < 4.4.0.55
  - api_manager >= 4.5.0 < 4.5.0.38
  - api_manager >= 4.6.0 < 4.6.0.3
  - api_control_plane >= 4.5.0 < 4.5.0.39
  - api_control_plane >= 4.6.0 < 4.6.0.3
  - universal_gateway >= 4.5.0 < 4.5.0.37
  - universal_gateway >= 4.6.0 < 4.6.0.3
  - traffic_manager >= 4.5.0 < 4.5.0.37
  - traffic_manager >= 4.6.0 < 4.6.0.3
  - >-
    org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.28.116 <
    9.28.116.391
  - >-
    org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.29.120 <
    9.29.120.210
  - 'org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.30.67 < 9.30.67.133'
  - 'org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.31.86 < 9.31.86.100'
  - 'org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.32.147 < 9.32.147.2'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-02-20T20:32:33.048480Z'
published: '2026-02-19'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T15:27:31.923Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-13590'
references:
  - url: >-
      https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4849/
tags:
  - cve.org
epss: 0.00703
epssPercentile: 0.51264
ingestedAt: '2026-09-23T16:27:22.665Z'
---

## Overview

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. 

 By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

## Affected

- `api_manager >= 4.2.0 < 4.2.0.179`
- `api_manager >= 4.3.0 < 4.3.0.91`
- `api_manager >= 4.4.0 < 4.4.0.55`
- `api_manager >= 4.5.0 < 4.5.0.38`
- `api_manager >= 4.6.0 < 4.6.0.3`
- `api_control_plane >= 4.5.0 < 4.5.0.39`
- `api_control_plane >= 4.6.0 < 4.6.0.3`
- `universal_gateway >= 4.5.0 < 4.5.0.37`
- `universal_gateway >= 4.6.0 < 4.6.0.3`
- `traffic_manager >= 4.5.0 < 4.5.0.37`
- `traffic_manager >= 4.6.0 < 4.6.0.3`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.28.116 < 9.28.116.391`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.29.120 < 9.29.120.210`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.30.67 < 9.30.67.133`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.31.86 < 9.31.86.100`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.32.147 < 9.32.147.2`

## Remediation

Follow the instructions given on  https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4849/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4849/#solution
