critical Known exploitedREV. 01
CVE-2022-29464WSO2 Products — Unauthenticated File Upload to Remote Code Execution
Several enterprise middleware products (WSO2 API Manager, Identity Server) take an unauthenticated upload whose filename escapes into the web root, so an attacker drops a web shell and runs code on the server. Enterprise Integrator is affected too.
Read the risk
THE VITAL STATS- CVSS score
- 9.8/ 10 CVSS v3.1
- EPSS probability
- 100% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2022-04-18
- Added to KEV
- 2022-04-25
- Exploit published
- Yes
- Confidence
- high
- Kill chain
- initial access
- MITRE ATT&CK
- T1190, T1505.003
- Severity
- critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attacker needsNetwork access to the product's /fileupload endpoint. No credentials needed.
Behind the card
4 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02Vendor advisoryWSO2 security advisorysecurity.docs.wso2.com
- 03ExploitPublic proof-of-concept exploitgithub.com
- 04CISACISA Known Exploited Vulnerabilities entrycisa.gov
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| title, summary, cvss, severity, exploitation.attack_complexity, exploitation.prerequisites, exploitation.exploit_available, mitre_attack, references | nvd.nist.gov | 2026-08-07 | claude-code | high |
| exploitation.known_exploited, remediation.patch_available, recommended_action | cisa.gov | 2026-08-07 | claude-code | high |
| epss | api.first.org | 2026-08-07 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.