---
id: CVE-2026-3418
title: >-
  Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows
  Remote Code Execution
summary: >-
  The System REST API accepts user-supplied file uploads without enforcing
  sufficient validation on the file type or destination, allowing files to be
  written to arbitrary server-accessible locations. Exploitation requires
  authenticated ad…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-434
vendor: WSO2
product: WSO2 API Manager
affected:
  - api_manager >= 4.4.0 < 4.4.0.67
  - api_manager >= 4.5.0 < 4.5.0.52
  - api_manager >= 4.6.0 < 4.6.0.16
  - traffic_manager >= 4.5.0 < 4.5.0.51
  - traffic_manager >= 4.6.0 < 4.6.0.16
  - api_control_plane >= 4.5.0 < 4.5.0.53
  - api_control_plane >= 4.6.0 < 4.6.0.17
  - universal_gateway >= 4.5.0 < 4.5.0.52
  - universal_gateway >= 4.6.0 < 4.6.0.16
  - 'org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.30.67 < 9.30.67.156'
  - 'org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.31.86 < 9.31.86.141'
  - 'org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.32.147 < 9.32.147.44'
  - >-
    org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common
    >= 9.30.67 < 9.30.67.156
  - >-
    org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common
    >= 9.31.86 < 9.31.86.141
  - >-
    org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common
    >= 9.32.147 < 9.32.147.44
  - 'org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api >= 9.30.67 < 9.30.67.156'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-07T17:46:58.452271Z'
published: '2026-08-06'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T15:30:30.610Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-3418'
references:
  - url: >-
      https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/
tags:
  - cve.org
epss: 0.00573
epssPercentile: 0.46109
ingestedAt: '2026-09-23T16:27:22.665Z'
---

## Overview

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges.

Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.

## Affected

- `api_manager >= 4.4.0 < 4.4.0.67`
- `api_manager >= 4.5.0 < 4.5.0.52`
- `api_manager >= 4.6.0 < 4.6.0.16`
- `traffic_manager >= 4.5.0 < 4.5.0.51`
- `traffic_manager >= 4.6.0 < 4.6.0.16`
- `api_control_plane >= 4.5.0 < 4.5.0.53`
- `api_control_plane >= 4.6.0 < 4.6.0.17`
- `universal_gateway >= 4.5.0 < 4.5.0.52`
- `universal_gateway >= 4.6.0 < 4.6.0.16`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.30.67 < 9.30.67.156`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.31.86 < 9.31.86.141`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl >= 9.32.147 < 9.32.147.44`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.30.67 < 9.30.67.156`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.31.86 < 9.31.86.141`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common >= 9.32.147 < 9.32.147.44`
- `org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api >= 9.30.67 < 9.30.67.156`

## Remediation

Follow the instructions given on  https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution
