CVE-2026-3418: WSO2 API Control Plane

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.

Affected products

  • WSO2 WSO2 API Control Plane: from 4.5.0, before 4.5.0.53 (fixed in 4.5.0.53); from 4.6.0, before 4.6.0.17 (fixed in 4.6.0.17)
  • WSO2 WSO2 API Manager: from 4.4.0, before 4.4.0.67 (fixed in 4.4.0.67); from 4.5.0, before 4.5.0.52 (fixed in 4.5.0.52); from 4.6.0, before 4.6.0.16 (fixed in 4.6.0.16)
  • WSO2 WSO2 API Manager Publisher Rest API v4: from 9.30.67, before 9.30.67.156 (fixed in 9.30.67.156); from 9.31.86, before 9.31.86.141 (fixed in 9.31.86.141); from 9.32.147, before 9.32.147.44 (fixed in 9.32.147.44)
  • WSO2 WSO2 Carbon API Management API: from 9.30.67, before 9.30.67.156 (fixed in 9.30.67.156)
  • WSO2 WSO2 Carbon API Management Implementation: from 9.30.67, before 9.30.67.156 (fixed in 9.30.67.156); from 9.31.86, before 9.31.86.141 (fixed in 9.31.86.141); from 9.32.147, before 9.32.147.44 (fixed in 9.32.147.44)
  • WSO2 WSO2 Traffic Manager: from 4.5.0, before 4.5.0.51 (fixed in 4.5.0.51); from 4.6.0, before 4.6.0.16 (fixed in 4.6.0.16)
  • WSO2 WSO2 Universal Gateway: from 4.5.0, before 4.5.0.52 (fixed in 4.5.0.52); from 4.6.0, before 4.6.0.16 (fixed in 4.6.0.16)

Published 2026-08-06. Last modified 2026-08-31.