Loading
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
Use CWE-434, Wso2 vendor hub and Api Control Plane product page to widen CVE-2025-13590 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-9312, CVE-2025-9804 and CVE-2025-6670 for nearby disclosures in the same product family.