Description

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

INFO

Published Date :

2026-02-19T10:05:06.083Z

Last Modified :

2026-03-06T05:44:33.953Z

Source :

WSO2
AFFECTED PRODUCTS

The following products are affected by CVE-2025-13590 vulnerability.

Vendors Products
Wso2
  • Api Control Plane
  • Api Manager
  • Org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
  • Org.wso2.carbon.apimgt Org.wso2.carbon.apimgt.impl
  • Traffic Manager
  • Universal Gateway
  • Wso2 Api Control Plane
  • Wso2 Api Manager
  • Wso2 Traffic Manager
  • Wso2 Universal Gateway
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-13590.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact