Forged admin tokens for WSO2 API Manager flaw CVE-2026-5430 (CVSS 10.0) hit honeypots 133 days after the fix. CISA's KEV entry describes the wrong bug.
WSO2 fixed a maximum-severity authentication bypass in its API Manager and gateway products on 3 May 2026. On 13 September, 133 days later, a forged administrator token landed in watchTowr's honeypot network. CISA added the flaw, CVE-2026-5430, to its Known Exploited Vulnerabilities catalog on 24 September and gave federal agencies until 27 September to deal with it. Anyone still running an unpatched WSO2 API Manager, API Control Plane, Traffic Manager or Universal Gateway should assume the patch gap is now being used.
The bug is simple to state. WSO2's JWT authentication accepts a token signed with an algorithm it does not support, and then treats that token as valid. An attacker writes their own token, sets an unsupported algorithm, fills in whatever claims they like, and gets in. WSO2 scores it CVSS 10.0, or 9.8 in single-tenant deployments, and says it can lead to "full account takeover", administrative accounts included.
What happened
WSO2 published security advisory WSO2-2026-5328 on 3 May 2026. Its summary: "JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access." The flaw was reported by the Hacktron Team. (SecurityWeek dates the fix to April; the advisory itself is dated 3 May.)
The CVE record followed on 6 August, when NVD published CVE-2026-5430. It classes the bug as CWE-347, improper verification of a cryptographic signature, with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H: network-reachable, low complexity, no credentials, no user interaction. No technical write-up or public exploit accompanied it.
That did not last. watchTowr's honeypots caught the first exploitation attempt on 13 September: a JWT carrying administrator privileges, sent to one of its research sensors. watchTowr then replayed that forged token against a vulnerable WSO2 deployment and bypassed authentication with it. The firm had already rebuilt the bug from WSO2's patch. SecurityWeek and The Hacker News reported the attacks on 16 September.
CISA listed CVE-2026-5430 in KEV on 24 September, with a due date of 27 September, three days later, and flagged it for forensic triage under BOD 26-04.
How a forged token becomes an admin session: the JWT check accepts an algorithm it does not support. Rotate secrets if the deployment was exposed while unpatched.
Why a forged token is so damaging here
An API manager is where an organisation keeps the keys to its other systems. According to the reporting on watchTowr's findings, a forged admin token gives access to API backend endpoints, credentials, and the consumer keys and secrets of every registered application. Those secrets keep working after the gateway is patched. So a deployment that was exposed between May and the day it was updated may already have leaked credentials that need rotating, even though the hole itself is now closed.
WSO2 has nearly 1,000 enterprise customers, according to SecurityWeek, concentrated in banking, government, telecoms and logistics.
CISA's entry describes a different bug
The KEV entry for CVE-2026-5430 does not match the vulnerability. CISA names it "WSO2 Multiple Products Path Traversal Vulnerability" and describes "a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution." That wording is still in the catalog as of its 1 October release.
WSO2's advisory and the NVD record both describe a JWT algorithm bypass and nothing about file upload. The KEV entry's own weakness field agrees with them: it lists CWE-347, the signature-verification class, not a path traversal CWE. The file-upload wording reads like WSO2's earlier KEV entry, CVE-2022-29464 ("unrestricted file upload, resulting in remote code execution"). TF treats the vendor and NVD description as correct and the KEV text as an error.
The KEV entry's name and description do not match the vendor advisory or the NVD record; its CWE-347 does. Triage from WSO2's advisory.
It matters for one practical reason. A team triaging from the KEV feed alone may go hunting for uploaded web shells and path-traversal requests, and miss the forged-token logins and stolen API secrets that this bug actually produces. The CVE ID, the affected products and the remediation link in the entry are all correct; only the name and description are wrong.
Affected products and fixed versions
| Product | Affected | Fixed at update level |
|---|---|---|
| API Manager | 4.1.0 to 4.6.0 | 4.1.0 U257, 4.2.0 U197, 4.3.0 U108, 4.4.0 U72, 4.5.0 U57, 4.6.0 U21 |
| API Control Plane | 4.5.0, 4.6.0 | 4.5.0 U58, 4.6.0 U22 |
| Traffic Manager | 4.5.0, 4.6.0 | 4.5.0 U56, 4.6.0 U21 |
| Universal Gateway | 4.5.0, 4.6.0 | 4.5.0 U57, 4.6.0 U21 |
Update levels are taken from the NVD record's version ranges. NVD marks API Manager releases before 4.1.0 as "unknown" rather than unaffected.
Open-source users without a WSO2 subscription get no update levels. WSO2 points them to two pull requests instead, #13752 in carbon-apimgt and #14167 in product-apim, or to an upgrade to a fixed release.
What defenders should do
- Patch now to the update level above for each product and version, or apply the two pull requests on open-source builds.
- Take management interfaces off the internet, or restrict them to known administrative networks.
- Hunt for forged tokens. Review authentication logs from May onward for JWTs with unexpected
algvalues and for administrator sessions you cannot account for. - Check for changes. Look over API definitions, applications and gateway configuration for edits nobody made on purpose.
- Rotate secrets if the deployment was exposed while unpatched: consumer keys and secrets, backend credentials, and service-account tokens held in the platform.
- Do not triage from the KEV text. Use WSO2's advisory for what to look for, not the path-traversal description.
Sources
- WSO2 security advisory WSO2-2026-5328 (CVE-2026-5430)
- NVD: CVE-2026-5430
- CISA Known Exploited Vulnerabilities catalog
- SecurityWeek: Enterprises warned of attacks exploiting WSO2 vulnerability
- The Hacker News: Active exploitation attempts target WSO2 API Manager JWT bypass
- Field Effect: Exploitation attempts target WSO2 authentication bypass vulnerability