All CVEs
Vulnerability intelligence

CVE-2026-3418

WSO2 WSO2 API Manager CWE-434

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.

CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.6%
Riskier than 46% of all CVEs · checked 2026-09-13
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Aug 7, 2026 · latest Aug 7, 2026

Coverage timeline

Related CVEs — WSO2