CVE-2025-13590Disclosure(wso2 / api_control_plane)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wso2 api_control_plane systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • api_control_plane
  • api_manager
  • traffic_manager
  • universal_gateway

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
api_control_planeapi_managertraffic_manageruniversal_gateway

5 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-19: 2Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 102-1902-20
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure2
2026-02-201
Patch1
Full discourse3 posts
  • CCB Alert@CCBalert
    Patch

    Warning: #RCE vulnerabilities in #WSO2 API Manager and Identity Server. #CVE-2025-13590 (CVSS 9.1) allows arbitrary file upload in API Manager, while #CVE-2025-12107 (CVSS 8.4) enables template injection in Identity Server. #Patch #Patch #Patch More info: https://security.docs.wso2.com/en/latest/security-announcements/

    Post summary

    WSO2 API Manager and Identity Server are affected by high‑severity RCE vulnerabilities (CVE‑2025‑13590 and CVE‑2025‑12107), with patches available via official documentation.

    01032334
    7.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-13590 - Critical A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to rem... https://www.thehackerwire.com/vulnerability/CVE-2025-13590/ https://t.co/i3SWbSIjy1

    Post summary

    The post announces CVE-2025-13590, detailing an arbitrary‑file‑upload vulnerability through a REST API that may lead to remote code execution; no exploit, active use, patch, or debunking is reported.

    0000032
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-13590** is a critical security flaw affecting systems that expose a REST API allowing administrative file uploads. The vulnerability permits a malicious actor with **administrative privileges** to upload arbitrary files to a **user-controlled location** within the deployment environment. If exploited successfully, this can lead to **remote code execution (RCE)**, enabling an attacker to execute arbitrary code on the affected system remotely. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2025-13590

    Post summary

    The post announces CVE-2025-13590, a critical REST API flaw that permits administrators to upload files to arbitrary locations, enabling remote code execution.

    0000036
    20 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2api_control_plane4.5.0--
Appwso2api_control_plane4.6.0--
Appwso2api_manager4.2.0--
Appwso2api_manager4.3.0--
Appwso2api_manager4.4.0--
Appwso2api_manager4.5.0--
Appwso2api_manager4.6.0--
Appwso2traffic_manager4.5.0--
Appwso2traffic_manager4.6.0--
Appwso2universal_gateway4.5.0--
Appwso2universal_gateway4.6.0--

Explore more