{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-3418","assignerOrgId":"ed10eef1-636d-4fbe-9993-6890dfa878f8","state":"PUBLISHED","assignerShortName":"WSO2","dateReserved":"2026-03-01T18:52:59.606Z","datePublished":"2026-08-06T17:32:14.823Z","dateUpdated":"2026-08-07T17:47:09.220Z"},"containers":{"cna":{"providerMetadata":{"orgId":"ed10eef1-636d-4fbe-9993-6890dfa878f8","shortName":"WSO2","dateUpdated":"2026-08-06T17:32:14.823Z"},"title":"Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-434","description":"CWE-434: Unrestricted Upload of File with Dangerous Type","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-232","descriptions":[{"lang":"en","value":"CAPEC-232 CAPEC-232: File Upload Vulnerability"}]}],"affected":[{"vendor":"WSO2","product":"WSO2 API Manager","versions":[{"status":"affected","version":"4.4.0","lessThan":"4.4.0.67","versionType":"custom"},{"status":"affected","version":"4.5.0","lessThan":"4.5.0.52","versionType":"custom"},{"status":"affected","version":"4.6.0","lessThan":"4.6.0.16","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"WSO2","product":"WSO2 Traffic Manager","versions":[{"status":"affected","version":"4.5.0","lessThan":"4.5.0.51","versionType":"custom"},{"status":"affected","version":"4.6.0","lessThan":"4.6.0.16","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"WSO2","product":"WSO2 API Control Plane","versions":[{"status":"affected","version":"4.5.0","lessThan":"4.5.0.53","versionType":"custom"},{"status":"affected","version":"4.6.0","lessThan":"4.6.0.17","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"WSO2","product":"WSO2 Universal Gateway","versions":[{"status":"affected","version":"4.5.0","lessThan":"4.5.0.52","versionType":"custom"},{"status":"affected","version":"4.6.0","lessThan":"4.6.0.16","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"WSO2","product":"WSO2 Carbon API Management Implementation","packageName":"org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl","versions":[{"status":"affected","version":"9.30.67","lessThan":"9.30.67.156","versionType":"custom"},{"status":"affected","version":"9.31.86","lessThan":"9.31.86.141","versionType":"custom"},{"status":"affected","version":"9.32.147","lessThan":"9.32.147.44","versionType":"custom"},{"status":"unaffected","version":"9.33.104","lessThanOrEqual":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"WSO2","product":"WSO2 API Manager Publisher REST API V4","packageName":"org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common","versions":[{"status":"affected","version":"9.30.67","lessThan":"9.30.67.156","versionType":"custom"},{"status":"affected","version":"9.31.86","lessThan":"9.31.86.141","versionType":"custom"},{"status":"affected","version":"9.32.147","lessThan":"9.32.147.44","versionType":"custom"},{"status":"unaffected","version":"9.33.104","lessThanOrEqual":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"WSO2","product":"WSO2 Carbon API Management API","packageName":"org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api","versions":[{"status":"affected","version":"9.30.67","lessThan":"9.30.67.156","versionType":"custom"},{"status":"unaffected","version":"9.33.104","lessThanOrEqual":"*","versionType":"custom"}],"defaultStatus":"unknown"}],"cpeApplicability":[{"operator":"OR","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"4.4.0","versionEndExcluding":"4.4.0.67"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5.0","versionEndExcluding":"4.5.0.52"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6.0","versionEndExcluding":"4.6.0.16"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5.0","versionEndExcluding":"4.5.0.51"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6.0","versionEndExcluding":"4.6.0.16"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5.0","versionEndExcluding":"4.5.0.53"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6.0","versionEndExcluding":"4.6.0.17"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5.0","versionEndExcluding":"4.5.0.52"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6.0","versionEndExcluding":"4.6.0.16"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*","versionStartIncluding":"9.30.67","versionEndExcluding":"9.30.67.156"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*","versionStartIncluding":"9.31.86","versionEndExcluding":"9.31.86.141"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*","versionStartIncluding":"9.32.147","versionEndExcluding":"9.32.147.44"},{"vulnerable":false,"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*","versionStartIncluding":"9.33.104","versionEndIncluding":"*"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_api_manager_publisher_rest_api_v4:*:*:*:*:*:*:*:*","versionStartIncluding":"9.30.67","versionEndExcluding":"9.30.67.156"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_api_manager_publisher_rest_api_v4:*:*:*:*:*:*:*:*","versionStartIncluding":"9.31.86","versionEndExcluding":"9.31.86.141"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_api_manager_publisher_rest_api_v4:*:*:*:*:*:*:*:*","versionStartIncluding":"9.32.147","versionEndExcluding":"9.32.147.44"},{"vulnerable":false,"criteria":"cpe:2.3:a:wso2:wso2_api_manager_publisher_rest_api_v4:*:*:*:*:*:*:*:*","versionStartIncluding":"9.33.104","versionEndIncluding":"*"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_api:*:*:*:*:*:*:*:*","versionStartIncluding":"9.30.67","versionEndExcluding":"9.30.67.156"},{"vulnerable":false,"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_api:*:*:*:*:*:*:*:*","versionStartIncluding":"9.33.104","versionEndIncluding":"*"}]}]}],"descriptions":[{"lang":"en","value":"The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges.\n\nSuccessful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.","supportingMedia":[{"type":"text/html","base64":false,"value":"The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges.\n\nSuccessful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution."}]}],"references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":9.1,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution","supportingMedia":[{"type":"text/html","base64":false,"value":"<span style=\"background-color: transparent;\">Follow the instructions given on </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution\"><span style=\"background-color: transparent;\">https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution</span></a> <br>"}]}],"source":{"advisory":"WSO2-2026-5146","discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-07T17:46:58.452271Z","id":"CVE-2026-3418","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-07T17:47:09.220Z"}}]}}