CVE-2025-1862: WSO2 Enterprise Integrator

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this vulnerability, an attacker can upload a specially crafted payload and achieve remote code execution (RCE), potentially compromising the server and its data.

Affected products

  • WSO2 Enterprise Integrator: version 6.6.0 only
  • WSO2 Identity Server: version 5.10.0 only; version 5.11.0 only; version 6.0.0 only; version 6.1.0 only
  • WSO2 Identity Server As Key Manager: version 5.10.0 only
  • WSO2 Open Banking Iam: version 2.0.0 only

Published 2025-09-26. Last modified 2026-06-17.