{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-3418","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-07T17:46:58.452271Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-07T17:47:09.220Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"WSO2 API Manager","vendor":"WSO2","versions":[{"lessThan":"4.4.0.67","status":"affected","version":"4.4.0","versionType":"custom"},{"lessThan":"4.5.0.52","status":"affected","version":"4.5.0","versionType":"custom"},{"lessThan":"4.6.0.16","status":"affected","version":"4.6.0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"WSO2 Traffic Manager","vendor":"WSO2","versions":[{"lessThan":"4.5.0.51","status":"affected","version":"4.5.0","versionType":"custom"},{"lessThan":"4.6.0.16","status":"affected","version":"4.6.0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"WSO2 API Control Plane","vendor":"WSO2","versions":[{"lessThan":"4.5.0.53","status":"affected","version":"4.5.0","versionType":"custom"},{"lessThan":"4.6.0.17","status":"affected","version":"4.6.0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"WSO2 Universal Gateway","vendor":"WSO2","versions":[{"lessThan":"4.5.0.52","status":"affected","version":"4.5.0","versionType":"custom"},{"lessThan":"4.6.0.16","status":"affected","version":"4.6.0","versionType":"custom"}]},{"defaultStatus":"unknown","packageName":"org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl","product":"WSO2 Carbon API Management Implementation","vendor":"WSO2","versions":[{"lessThan":"9.30.67.156","status":"affected","version":"9.30.67","versionType":"custom"},{"lessThan":"9.31.86.141","status":"affected","version":"9.31.86","versionType":"custom"},{"lessThan":"9.32.147.44","status":"affected","version":"9.32.147","versionType":"custom"},{"lessThanOrEqual":"*","status":"unaffected","version":"9.33.104","versionType":"custom"}]},{"defaultStatus":"unknown","packageName":"org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.publisher.v1.common","product":"WSO2 API Manager Publisher REST API V4","vendor":"WSO2","versions":[{"lessThan":"9.30.67.156","status":"affected","version":"9.30.67","versionType":"custom"},{"lessThan":"9.31.86.141","status":"affected","version":"9.31.86","versionType":"custom"},{"lessThan":"9.32.147.44","status":"affected","version":"9.32.147","versionType":"custom"},{"lessThanOrEqual":"*","status":"unaffected","version":"9.33.104","versionType":"custom"}]},{"defaultStatus":"unknown","packageName":"org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.api","product":"WSO2 Carbon API Management API","vendor":"WSO2","versions":[{"lessThan":"9.30.67.156","status":"affected","version":"9.30.67","versionType":"custom"},{"lessThanOrEqual":"*","status":"unaffected","version":"9.33.104","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.4.0.67","versionStartIncluding":"4.4.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.0.52","versionStartIncluding":"4.5.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.6.0.16","versionStartIncluding":"4.6.0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.0.51","versionStartIncluding":"4.5.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"4.6.0.16","versionStartIncluding":"4.6.0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.0.53","versionStartIncluding":"4.5.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*","versionEndExcluding":"4.6.0.17","versionStartIncluding":"4.6.0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.0.52","versionStartIncluding":"4.5.0","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:*","versionEndExcluding":"4.6.0.16","versionStartIncluding":"4.6.0","vulnerable":true}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*","versionEndExcluding":"9.30.67.156","versionStartIncluding":"9.30.67","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*","versionEndExcluding":"9.31.86.141","versionStartIncluding":"9.31.86","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*","versionEndExcluding":"9.32.147.44","versionStartIncluding":"9.32.147","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*","versionEndIncluding":"*","versionStartIncluding":"9.33.104","vulnerable":false}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_api_manager_publisher_rest_api_v4:*:*:*:*:*:*:*:*","versionEndExcluding":"9.30.67.156","versionStartIncluding":"9.30.67","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager_publisher_rest_api_v4:*:*:*:*:*:*:*:*","versionEndExcluding":"9.31.86.141","versionStartIncluding":"9.31.86","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager_publisher_rest_api_v4:*:*:*:*:*:*:*:*","versionEndExcluding":"9.32.147.44","versionStartIncluding":"9.32.147","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_api_manager_publisher_rest_api_v4:*:*:*:*:*:*:*:*","versionEndIncluding":"*","versionStartIncluding":"9.33.104","vulnerable":false}],"negate":false,"operator":"OR"},{"cpeMatch":[{"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_api:*:*:*:*:*:*:*:*","versionEndExcluding":"9.30.67.156","versionStartIncluding":"9.30.67","vulnerable":true},{"criteria":"cpe:2.3:a:wso2:wso2_carbon_api_management_api:*:*:*:*:*:*:*:*","versionEndIncluding":"*","versionStartIncluding":"9.33.104","vulnerable":false}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"finder","value":"Thilan Dissanayaka"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges.\n\nSuccessful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution."}],"value":"The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges.\n\nSuccessful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution."}],"impacts":[{"capecId":"CAPEC-232","descriptions":[{"lang":"en","value":"CAPEC-232 CAPEC-232: File Upload Vulnerability"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-434","description":"CWE-434: Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-23T15:30:30.610Z","orgId":"ed10eef1-636d-4fbe-9993-6890dfa878f8","shortName":"WSO2"},"references":[{"tags":["vendor-advisory"],"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span style=\"background-color: transparent;\">Follow the instructions given on </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution\"><span style=\"background-color: transparent;\">https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution</span></a> <br>"}],"value":"Follow the instructions given on  https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5146/#solution"}],"source":{"advisory":"WSO2-2026-5146","discovery":"INTERNAL"},"title":"Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"ed10eef1-636d-4fbe-9993-6890dfa878f8","assignerShortName":"WSO2","cveId":"CVE-2026-3418","datePublished":"2026-08-06T17:32:14.823Z","dateReserved":"2026-03-01T18:52:59.606Z","dateUpdated":"2026-09-23T15:30:30.610Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"}