Impact
The System REST API accepts file uploads without validating the file type or destination, allowing an authenticated publisher to write files to any server‑accessible location on the platform. This flaw can be leveraged to deliver malicious code that may execute when the uploaded content is processed or accessed, providing the attacker with remote code execution capabilities. The weakness stems from an improper file handling mechanism classified as CWE‑434.
Affected Systems
The vulnerability affects multiple WSO2 products, including the API Control Plane, API Manager, API Manager Publisher REST API V4, Carbon API Management API and Implementation, Traffic Manager, and Universal Gateway. Versions are not specified in the advisory, so all released releases before the fix should be considered vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity assessment. No EPSS score is provided, and the issue is not currently listed in CISA’s KEV catalog, but the requirement for authenticated publisher privileges means that any compromised or misconfigured administrative account could be used to exploit the flaw. Successful exploitation would enable attackers to place malicious files on the server, potentially leading to arbitrary code execution and full system compromise. The exploitation pathway relies on the REST API’s lack of file type and path validation, combined with existent administrative access, and therefore represents a significant risk to any organization running the affected WSO2 products.
OpenCVE Enrichment