Vulnerability
CVE-2026-5430
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- TLP:CLEAR
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 01:44
Description
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
Aliases and classifications
CWE-347Improper Validation of Certificate with Host Mismatch
Minimised technical details
No raw data- cisa kev
- True
- cvss score
- 10
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- cvss severity
- CRITICAL
Provenance
Public references
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.