CVE-2026-3418

Die System-REST-API akzeptiert von Benutzern bereitgestellte Dateiuploads ohne ausreichende Überprüfung des Dateityps oder der Zielorte u…

criticalEPSS 0.8%

Description

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.

Metrics

9.1
Source: cna-v3
54.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-06 17:32 UTC
CWE-434

Weakness classes (CWE)

  • CWE-434Base

    Unrestricted Upload of File with Dangerous Type

    The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-07 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-3418","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
  2. New CVE Received2026-08-06 22:17 UTC· ed10eef1-636d-4fbe-9993-6890dfa878f8
    • Affected: WSO2 API Manager, WSO2 Traffic Manager, WSO2 API Control Plane (+4)
    • Description: The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-434

Linked advisories