Wso2 Carbon Api Management Api
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Wso2 Carbon Api Management Api.
By the Year
In 2026 there have been 1 vulnerability in Wso2 Carbon Api Management Api with an average score of 9.1 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 9.10 |
It may take a day or so for new Wso2 Carbon Api Management Api vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Wso2 Carbon Api Management Api Security Vulnerabilities
WSO2 API Manager: Arbitrary File Upload via REST API, RCE via Auth
CVE-2026-3418
9.1 - Critical
- August 06, 2026
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.
Unrestricted File Upload
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Wso2 Carbon Api Management Api or by Wso2? Click the Watch button to subscribe.