CVE Database
/

CVE-2025-13590

Back to search

CVE-2025-13590

Published: Feb 19, 2026

Modified: Mar 6, 2026

PUBLISHED

CVSS v3.1

9.1

CRITICAL

Description

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

VendorProductVersions

WSO2

WSO2 API Manager

unaffected
0 - < 4.2.0
affected
4.2.0 - < 4.2.0.179
affected
4.3.0 - < 4.3.0.91
affected
4.4.0 - < 4.4.0.55
affected
4.5.0 - < 4.5.0.38

+1 more versions

WSO2

WSO2 API Control Plane

unknown
0 - < 4.5.0
affected
4.5.0 - < 4.5.0.39
affected
4.6.0 - < 4.6.0.3

WSO2

WSO2 Universal Gateway

unknown
0 - < 4.5.0
affected
4.5.0 - < 4.5.0.37
affected
4.6.0 - < 4.6.0.3

WSO2

WSO2 Traffic Manager

unknown
0 - < 4.5.0
affected
4.5.0 - < 4.5.0.37
affected
4.6.0 - < 4.6.0.3

WSO2

org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl

affected
9.28.116 - < 9.28.116.391
affected
9.29.120 - < 9.29.120.210
affected
9.30.67 - < 9.30.67.133
affected
9.31.86 - < 9.31.86.100
affected
9.32.147 - < 9.32.147.2

+1 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now