CVE-2025-10907
WSO2 API Manager vulnerability analysis and mitigation

Overview

CVE-2025-10907 is an arbitrary file upload vulnerability (CWE-434) affecting multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. Authenticated administrative users can upload specially crafted files to user-controlled locations within the deployment, potentially leading to remote code execution (RCE). Affected products include WSO2 API Manager (versions 3.1.0–4.5.0), WSO2 Identity Server (versions 5.10.0–7.1.0), WSO2 Enterprise Integrator (6.6.0), WSO2 Open Banking AM/IAM (2.0.0), WSO2 API Control Plane (4.5.0), WSO2 Traffic Manager (4.5.0), and WSO2 Universal Gateway (4.5.0). The CVE was published on November 5, 2025, with NVD initial analysis completed December 4, 2025. The CVSS v3.1 base score is 7.2 (High) per NVD/NIST, and 8.4 (High) per the CNA (WSO2) (WSO2 Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): the affected WSO2 SOAP admin services fail to adequately validate both the content type and the destination path of uploaded files, allowing an attacker to place arbitrary files — including executable code — into user-controlled locations within the server deployment. Exploitation requires network access to the SOAP admin service endpoint and valid administrative credentials; no user interaction is required. Depending on how the server processes the uploaded file (e.g., if it is placed in a web-accessible or auto-deployed directory), the file may be executed, resulting in RCE. No public proof-of-concept code has been identified at this time (WSO2 Advisory, Red Hat CVE).

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code on the affected server, resulting in high confidentiality, integrity, and availability impact across the compromised system. An attacker who achieves RCE could exfiltrate sensitive data (API keys, identity credentials, configuration secrets), modify or destroy application data, pivot to other internal systems, or establish persistent backdoor access. The scope of impact is limited to the affected deployment by default, but lateral movement within the enterprise network is feasible once the server is compromised (WSO2 Advisory, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of this report. The vulnerability requires administrative credentials to exploit, which significantly limits the attack surface. The EPSS score is approximately 0.063% (0.000630), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 733382) (WSO2 Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible WSO2 product instances (API Manager, Identity Server, Enterprise Integrator, etc.) running affected versions using network scanning tools or Shodan/Censys queries targeting WSO2 service banners.
  2. Credential Acquisition: Obtain valid administrative credentials for the target WSO2 deployment through phishing, credential stuffing, or insider access — exploitation requires administrative privileges on the SOAP admin services.
  3. Access SOAP Admin Service: Authenticate to the WSO2 SOAP admin service endpoint (typically accessible at paths such as /services/ on the management port, e.g., port 9443) using the obtained credentials.
  4. Craft Malicious File: Prepare a specially crafted file (e.g., a JSP web shell or a deployable archive) designed to execute arbitrary commands when processed by the server.
  5. Upload File via SOAP Request: Submit a SOAP request to the vulnerable admin service operation that handles file uploads, specifying a user-controlled destination path within the deployment directory (e.g., a web-accessible folder or auto-deployment directory).
  6. Trigger Execution: Access the uploaded file via the web server (e.g., by navigating to its URL if placed in a web-accessible directory) or wait for the server to auto-process/deploy it, achieving remote code execution as the WSO2 service account (WSO2 Advisory).

Indicators of compromise

  • Network: Unusual SOAP requests (HTTP POST with SOAPAction headers) to WSO2 admin service endpoints (e.g., /services/) from unexpected source IPs; outbound connections from the WSO2 server to unknown external hosts following admin service activity.
  • Logs: WSO2 management console or Carbon logs (wso2carbon.log) showing file upload operations to non-standard or web-accessible directories; authentication events for admin accounts from anomalous IP addresses or at unusual times.
  • File System: Unexpected files (especially .jsp, .war, .jag, or script files) appearing in WSO2 deployment directories such as <WSO2_HOME>/repository/deployment/server/webapps/ or similar auto-deploy paths; newly created files with web shell characteristics (e.g., containing Runtime.exec, ProcessBuilder, or similar Java RCE patterns).
  • Process: Unusual child processes spawned by the WSO2 Java process (e.g., sh, bash, cmd.exe, curl, wget, powershell) indicating command execution via an uploaded web shell.

Mitigation and workarounds

WSO2 has released patched versions for all affected products; administrators should upgrade immediately to the fixed builds listed in the official advisory (e.g., API Manager ≥4.5.0.28, Identity Server ≥7.1.0.31, Enterprise Integrator ≥6.6.0.224, and corresponding patch builds for all other affected versions). As a workaround, restrict network access to WSO2 SOAP admin service endpoints (typically on port 9443) to trusted administrative hosts only, using firewall rules or network segmentation. Additionally, enforce the principle of least privilege by auditing and minimizing the number of accounts with administrative access to SOAP services, and implement monitoring and alerting on admin service file upload operations (WSO2 Advisory).

Community reactions

Red Hat has tracked this CVE and published a security advisory page, indicating awareness among enterprise Linux and middleware vendors (Red Hat CVE). The vulnerability was noted in automated CVE tracking feeds and security blogs shortly after publication, but no significant independent researcher commentary or major media coverage has been identified. Community sentiment appears measured given the administrative privilege requirement, which limits the practical risk for most deployments.

Additional resources


SourceThis report was generated using AI

Related WSO2 API Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5430CRITICAL10
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-1728CRITICAL9.8
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2025-15039CRITICAL9.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026
CVE-2026-0637MEDIUM4.4
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:identity_server
NoYesAug 06, 2026
CVE-2025-13736LOW3.7
  • WSO2 API Manager logoWSO2 API Manager
  • cpe:2.3:a:wso2:api_manager
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management