CVE-2026-5430: WSO2 Multiple Products
WSO2 API Control Plane,API管理器,交通管理器和Universal Gateway包含一個路徑的traversal脆弱性,可以允許不受限制的檔案上傳,並導致遠端程式碼執行。
CISA (English)
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
- 廠商
- WSO2
- 產品
- Multiple Products
- 漏洞
- WSO2 Multiple Products Path Traversal Vulnerability
- 加入日期
- 2026年9月24日
- CISA 修補期限(美國聯邦機關)
- 2026年9月27日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-347
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02