CVE-2026-3418
Last modified
CVE-2026-3418 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WSO2 | WSO2 API Manager | >= 4.4.0, < 4.4.0.67; >= 4.5.0, < 4.5.0.52; >= 4.6.0, < 4.6.0.16 |
| WSO2 | WSO2 Traffic Manager | >= 4.5.0, < 4.5.0.51; >= 4.6.0, < 4.6.0.16 |
| WSO2 | WSO2 API Control Plane | >= 4.5.0, < 4.5.0.53; >= 4.6.0, < 4.6.0.17 |
| WSO2 | WSO2 Universal Gateway | >= 4.5.0, < 4.5.0.52; >= 4.6.0, < 4.6.0.16 |
| WSO2 | WSO2 Carbon API Management Implementation | >= 9.30.67, < 9.30.67.156; >= 9.31.86, < 9.31.86.141; >= 9.32.147, < 9.32.147.44 |
| WSO2 | WSO2 API Manager Publisher REST API V4 | >= 9.30.67, < 9.30.67.156; >= 9.31.86, < 9.31.86.141; >= 9.32.147, < 9.32.147.44 |
| WSO2 | WSO2 Carbon API Management API | >= 9.30.67, < 9.30.67.156 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-3418?
How severe is CVE-2026-3418?
How do I fix CVE-2026-3418?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34172Giskard is an open-source Python library for testing and eva…8.8
- CVE-2026-34175Uncontrolled search path for some Hardware-Aware-Automated-M…5.4
- CVE-2026-34176When running in Appliance mode, an authenticated remote comm…8.7
- CVE-2026-34177Canonical LXD versions 4.12 through 6.7 contain an incomplet…9.1
- CVE-2026-34178In Canonical LXD before 6.8, the backup import path validate…9.1
- CVE-2026-34179In Canonical LXD versions 4.12 through 6.7, the doCertificat…9.1
- CVE-2026-34180Issue summary: Parsing a crafted DER-encoded ASN.1 structure…7.5
- CVE-2026-34181Issue Summary: The PKCS#12 file processing fails to perform …7.4
- CVE-2026-34182Issue Summary: Cryptographic Message Services (CMS) processi…9.1
- CVE-2026-34183Issue summary: Remote peer may exhaust heap memory of the QU…7.5
- CVE-2026-34184AlanWeb SCADA does not enforce authorization for some direct…9.1
- CVE-2026-34185AlanWeb SCADA is vulnerable to SQL Injection across most scr…8.8
Are you affected by CVE-2026-3418?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
