org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl vulnerabilities
CVEs whose affected-version data names the org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-3418Critical· 9.1Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated ad…
CVE-2026-3415High· 8.7XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service
The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-suppl…
CVE-2025-13590Critical· 9.1Authenticated arbitrary file upload via a System REST API requiring administrator permission.
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerabi…