CVE-2026-5430CISA KEVEPSS p46.3%
CVE-2026-5430WSO2 Multiple Products Path Traversal Vulnerability
WSO2 / Multiple Products
Description
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
Scoring
| CVSS | 10.0 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.59% probability of exploitation · percentile 46.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-25 |
CISA KEV entry
Added to KEV: 2026-09-24