EIP-2026-102434

PRE-CVE

WSO2 3.1.0 - Arbitrary File Delete

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102434. PoCs published by Raki Ben Hamouda.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file deletion vulnerability in WSO2 API Manager 3.1.0 via a path traversal attack in the `extensionName` parameter of the `/carbon/extensions/deleteExtension-ajaxprocessor.jsp` endpoint. The PoC shows how an authenticated attacker can delete system files by sending a crafted POST request.

Description

WSO2 3.1.0 - Arbitrary File Delete

Exploits (1)

exploitdb WORKING POC
by Raki Ben Hamouda · textwebappsjava
https://www.exploit-db.com/exploits/48313

This exploit demonstrates an arbitrary file deletion vulnerability in WSO2 API Manager 3.1.0 via a path traversal attack in the `extensionName` parameter of the `/carbon/extensions/deleteExtension-ajaxprocessor.jsp` endpoint. The PoC shows how an authenticated attacker can delete system files by sending a crafted POST request.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: WSO2 API Manager 3.1.0
Auth required
Prerequisites: Authenticated access to the WSO2 Carbon UI · Low-privilege user account
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026