Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2025-13590 |
| Alert Source | NVD - New Critical Vulnerability |
| CVE Publication Year | 2025 |
| Date Published | 2026-02-19 |
| Vendor | Wso2 |
| Product | Api Control Plane |
| CVSS Score | 9.1 (critical) |
| EPSS Score | 0.2% (percentile: 43%) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution.
By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
Required Actions
Apply vendor patches or mitigations as soon as available.
Who Is Affected?
This vulnerability affects Api Control Plane by Wso2. Check if your organization uses this software and requires updates.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
