CVE-2026-3418
Die System-REST-API akzeptiert von Benutzern bereitgestellte Dateiuploads ohne ausreichende Überprüfung des Dateityps oder der Zielorte u…
Description
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.
Metrics
Show all metrics
Weakness classes (CWE)
CWE-434Base
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-07 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-3418","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
- New CVE Received2026-08-06 22:17 UTC· ed10eef1-636d-4fbe-9993-6890dfa878f8
- Affected: WSO2 API Manager, WSO2 Traffic Manager, WSO2 API Control Plane (+4)
- Description: The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.
- CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-434