{"id":"CVE-2025-1862","details":"An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server.\n\n\nBy leveraging this vulnerability, an attacker can upload a specially crafted payload and achieve remote code execution (RCE), potentially compromising the server and its data.","modified":"2026-07-08T06:38:31.310782125Z","published":"2025-09-26T09:15:31.687Z","database_specific":{"unresolved_ranges":[{"vendor_product":"wso2:identity_server","cpes":["cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*","cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*","cpe:2.3:a:wso2:identity_server:6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:wso2:identity_server:6.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.10.0"},{"last_affected":"5.10.0"},{"introduced":"5.11.0"},{"last_affected":"5.11.0"},{"introduced":"6.0.0"},{"last_affected":"6.0.0"},{"introduced":"6.1.0"},{"last_affected":"6.1.0"}],"source":"CPE_STRING"},{"vendor_product":"wso2:identity_server_as_key_manager","cpes":["cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.10.0"},{"last_affected":"5.10.0"}],"source":"CPE_STRING"},{"cpes":["cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.0.0"}],"source":"CPE_STRING","vendor_product":"wso2:open_banking_iam"}]},"references":[{"type":"ADVISORY","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-3992/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wso2/product-ei","events":[{"introduced":"bfdf341ab6dcfccce35c88b8a1567604f07ba8f5"},{"last_affected":"bfdf341ab6dcfccce35c88b8a1567604f07ba8f5"}],"database_specific":{"cpe":"cpe:2.3:a:wso2:enterprise_integrator:6.6.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.6.0"},{"last_affected":"6.6.0"}],"source":"CPE_STRING"}}],"versions":["6.6.0","v6.6.0-rc3","v6.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1862.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}