CVE-2025-13590

HIGH WAF: Medium
CVSS 7.2 Published: 2026-02-19
CWE-434

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

WAF Coverage Analysis

Unrestricted File Upload Medium WAF Coverage

OWASP: A04:2021 Insecure Design

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
wso2api_control_plane4.5.0
wso2api_control_plane4.6.0
wso2api_manager4.2.0
wso2api_manager4.3.0
wso2api_manager4.4.0
wso2api_manager4.5.0
wso2api_manager4.6.0
wso2traffic_manager4.5.0
wso2traffic_manager4.6.0
wso2universal_gateway4.5.0

References

Back to CVE Database