← Back

CVE-2025-13590

nvd nist
Published: Feb 19, 2026Modified: Jun 18, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

Affected (11)

4 products
Api Control Plane
Api Manager
Traffic Manager
Universal Gateway
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
Version 4.5.0
Version 4.6.0
Wso2
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Version 4.6.0
Wso2
Version 4.5.0
Version 4.6.0
Wso2
Version 4.5.0
Version 4.6.0

References (1)

Timeline

No history available yet.