GHSA-p6jf-79j3-33f3CriticalCVSS 9.1

carbon-apimgt does not properly restrict uploaded files

Published
February 19, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution.

By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

🎯 Affected products1

  • maven/org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1:< 9.32.167

🔗 References (6)