critical Known exploitedREV. 01

CVE-2022-29464WSO2 Products — Unauthenticated File Upload to Remote Code Execution

Several enterprise middleware products (WSO2 API Manager, Identity Server) take an unauthenticated upload whose filename escapes into the web root, so an attacker drops a web shell and runs code on the server. Enterprise Integrator is affected too.

YOUR NEXT MOVE

Patch the affected WSO2 products per the vendor advisory; then hunt the deployment webapps directory for files nobody on your team put there.

Read the risk

THE VITAL STATS
CVSS score
9.8/ 10
CVSS v3.1
EPSS probability
100%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2022-04-18
Added to KEV
2022-04-25
Exploit published
Yes
Confidence
high
Kill chain
initial access
MITRE ATT&CK
T1190, T1505.003
Severity
critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attacker needsNetwork access to the product's /fileupload endpoint. No credentials needed.

Behind the card

4 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
title, summary, cvss, severity, exploitation.attack_complexity, exploitation.prerequisites, exploitation.exploit_available, mitre_attack, referencesnvd.nist.gov2026-08-07claude-codehigh
exploitation.known_exploited, remediation.patch_available, recommended_actioncisa.gov2026-08-07claude-codehigh
epssapi.first.org2026-08-07claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2022-29464 · CRDS 0.1 · Issued 2026-08-07