Security Advisory Desk
unratedQCS priority 76/100WSO2

CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability

Multiple WSO2 products have a vulnerability that lets attackers upload files without restriction. This can lead to running harmful code on the affected server, potentially compromising the entire system.

QCS published 6/10/2026, 8:39:39 pm ISTVendor disclosure 24/9/2026, 5:30:00 am ISTVerified 6/10/2026, 8:39:39 pm ISTRevision 1

In plain language

What this advisory means

Multiple WSO2 products have a vulnerability that lets attackers upload files without restriction. This can lead to running harmful code on the affected server, potentially compromising the entire system.

Technical explanation

How the issue affects the environment

WSO2's API Control Plane, API Manager, Traffic Manager, and Universal Gateway suffer from a path traversal vulnerability. This flaw allows attackers to bypass normal file upload restrictions by manipulating file paths, enabling them to upload arbitrary files. Exploiting this can result in remote code execution, giving attackers control over the affected system.

Operational impact

Why teams should care

If exploited, attackers can gain unauthorized access to systems, potentially leading to data breaches, service disruptions, and compromise of business operations. This undermines trust in the affected services and may expose organizations to regulatory and financial risks.

Immediate action

Organizations should apply all mitigations as per WSO2's official instructions. They must ensure compliance with CISA's Binding Operational Directive 26-04 for prioritizing security updates based on risk and follow forensic triage guidance. If mitigations are unavailable, consider discontinuing product use or following guidance appropriate to cloud services.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • CISA Known Exploited Vulnerabilities Catalog entry dated 2026-09-24
  • CISA Binding Operational Directive 26-04 (BOD 26-04) guidance on remediation and forensic triage
  • WSO2 security advisory URL referenced by CISA
  • NVD entry for CVE-2026-5430

Authoritative reference

CISA Known Exploited Vulnerabilities

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source