VYPR
Unrated severityNVD Advisory· Published Sep 26, 2025· Updated Feb 26, 2026

Authenticated Arbitrary File Upload in Multiple WSO2 Products via BPEL Uploader SOAP Service Leading to Remote Code Execution

CVE-2025-1862

Description

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server.

By leveraging this vulnerability, an attacker can upload a specially crafted payload and achieve remote code execution (RCE), potentially compromising the server and its data.

Affected products

4
  • WSO2/WSO2 Enterprise Integratorv5
    Range: 6.6.0
  • WSO2/WSO2 Identity Serverv5
    Range: 5.10.0
  • WSO2/WSO2 Identity Server as Key Managerv5
    Range: 5.10.0
  • WSO2/WSO2 Open Banking IAMv5
    Range: 2.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.