
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10907 is an arbitrary file upload vulnerability (CWE-434) affecting multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. Authenticated administrative users can upload specially crafted files to user-controlled locations within the deployment, potentially leading to remote code execution (RCE). Affected products include WSO2 API Manager (versions 3.1.0–4.5.0), WSO2 Identity Server (versions 5.10.0–7.1.0), WSO2 Enterprise Integrator (6.6.0), WSO2 Open Banking AM/IAM (2.0.0), WSO2 API Control Plane (4.5.0), WSO2 Traffic Manager (4.5.0), and WSO2 Universal Gateway (4.5.0). The CVE was published on November 5, 2025, with NVD initial analysis completed December 4, 2025. The CVSS v3.1 base score is 7.2 (High) per NVD/NIST, and 8.4 (High) per the CNA (WSO2) (WSO2 Advisory, Red Hat CVE).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): the affected WSO2 SOAP admin services fail to adequately validate both the content type and the destination path of uploaded files, allowing an attacker to place arbitrary files — including executable code — into user-controlled locations within the server deployment. Exploitation requires network access to the SOAP admin service endpoint and valid administrative credentials; no user interaction is required. Depending on how the server processes the uploaded file (e.g., if it is placed in a web-accessible or auto-deployed directory), the file may be executed, resulting in RCE. No public proof-of-concept code has been identified at this time (WSO2 Advisory, Red Hat CVE).
Successful exploitation grants an attacker the ability to execute arbitrary code on the affected server, resulting in high confidentiality, integrity, and availability impact across the compromised system. An attacker who achieves RCE could exfiltrate sensitive data (API keys, identity credentials, configuration secrets), modify or destroy application data, pivot to other internal systems, or establish persistent backdoor access. The scope of impact is limited to the affected deployment by default, but lateral movement within the enterprise network is feasible once the server is compromised (WSO2 Advisory, Red Hat CVE).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of this report. The vulnerability requires administrative credentials to exploit, which significantly limits the attack surface. The EPSS score is approximately 0.063% (0.000630), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 733382) (WSO2 Advisory, Red Hat CVE).
/services/ on the management port, e.g., port 9443) using the obtained credentials.SOAPAction headers) to WSO2 admin service endpoints (e.g., /services/) from unexpected source IPs; outbound connections from the WSO2 server to unknown external hosts following admin service activity.wso2carbon.log) showing file upload operations to non-standard or web-accessible directories; authentication events for admin accounts from anomalous IP addresses or at unusual times..jsp, .war, .jag, or script files) appearing in WSO2 deployment directories such as <WSO2_HOME>/repository/deployment/server/webapps/ or similar auto-deploy paths; newly created files with web shell characteristics (e.g., containing Runtime.exec, ProcessBuilder, or similar Java RCE patterns).sh, bash, cmd.exe, curl, wget, powershell) indicating command execution via an uploaded web shell.WSO2 has released patched versions for all affected products; administrators should upgrade immediately to the fixed builds listed in the official advisory (e.g., API Manager ≥4.5.0.28, Identity Server ≥7.1.0.31, Enterprise Integrator ≥6.6.0.224, and corresponding patch builds for all other affected versions). As a workaround, restrict network access to WSO2 SOAP admin service endpoints (typically on port 9443) to trusted administrative hosts only, using firewall rules or network segmentation. Additionally, enforce the principle of least privilege by auditing and minimizing the number of accounts with administrative access to SOAP services, and implement monitoring and alerting on admin service file upload operations (WSO2 Advisory).
Red Hat has tracked this CVE and published a security advisory page, indicating awareness among enterprise Linux and middleware vendors (Red Hat CVE). The vulnerability was noted in automated CVE tracking feeds and security blogs shortly after publication, but no significant independent researcher commentary or major media coverage has been identified. Community sentiment appears measured given the administrative privilege requirement, which limits the practical risk for most deployments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."