Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-5430

WSO2 Multiple Products Path Traversal to RCE

WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.

cat cve-2026-5430.json
Vendor
WSO2
Product
API Control Plane, API Manager, Traffic Manager, Universal Gateway
CVSS
10.0
EPSS (exploit probability)
0.6%
Status
kev
CISA patch-by (BOD 22-01)
Published

A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway allows an unauthenticated attacker to traverse directory paths, upload arbitrary files, and achieve remote code execution. No credentials or user interaction required.

WSO2 disclosed the flaw on August 6, 2026. Exploitation in enterprise environments was confirmed by September 13. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 24, 2026, with a BOD 26-04 remediation deadline of September 27 for federal civilian agencies.

CVSS base score is 10.0 in multi-tenant deployments. Patch via WSO2’s security advisory portal for your specific product version. If patching immediately is not possible, restrict external network access to WSO2 management interfaces and block affected upload paths at the perimeter.

Primary source: NVD CVE-2026-5430. Coverage: WSO2 CVSS 10 JWT Bypass Exploited in the Wild.