CVE-2025-13590 - Wso2 Api Control Plane, Wso2 Traffic Manager and Wso2 Api Manager

Critical 9.1

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

Affected software

Wso2 Api Control Plane

Wso2 Traffic Manager

Wso2 Api Manager

Wso2 Universal Gateway

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.