CVE-2025-13590: WSO2 API Control Plane
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
Affected products
- WSO2 API Control Plane: version 4.5.0 only; version 4.6.0 only
- WSO2 API Manager: version 4.2.0 only; version 4.3.0 only; version 4.4.0 only; version 4.5.0 only; version 4.6.0 only
- WSO2 Traffic Manager: version 4.5.0 only; version 4.6.0 only
- WSO2 Universal Gateway: version 4.5.0 only; version 4.6.0 only
Published 2026-02-19. Last modified 2026-06-18.