VYPR
Medium severity6.7NVD Advisory· Published Sep 26, 2025· Updated Jun 17, 2026

CVE-2025-1862

CVE-2025-1862

Description

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server.

By leveraging this vulnerability, an attacker can upload a specially crafted payload and achieve remote code execution (RCE), potentially compromising the server and its data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • WSO2/WSO2 Enterprise Integratorv5
    Range: 6.6.0
  • WSO2/WSO2 Identity Serverv5
    Range: 5.10.0
  • WSO2/WSO2 Open Banking IAMv5
    Range: 2.0.0
  • WSO2/WSO2 Identity Server as Key Managerv5
    Range: 5.10.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.