critical Cve 2026 5430 · Exploits

WSO2 API Manager JWT Bypass Exploited 133 Days After the Fix

Data graphic: timeline of WSO2 CVE-2026-5430. WSO2's advisory and fix on May 3, the CVE record on Aug 6 95 days later , the first forged admin token in a watchTowr honeypot on Sep 13 133 days after the fix , and CISA KEV on Sep 24.
AK

Threat intelligence editor · Updated Oct 2, 2026, 8:06 AM EDT

Forged admin tokens for WSO2 API Manager flaw CVE-2026-5430 (CVSS 10.0) hit honeypots 133 days after the fix. CISA's KEV entry describes the wrong bug.

WSO2 fixed a maximum-severity authentication bypass in its API Manager and gateway products on 3 May 2026. On 13 September, 133 days later, a forged administrator token landed in watchTowr's honeypot network. CISA added the flaw, CVE-2026-5430, to its Known Exploited Vulnerabilities catalog on 24 September and gave federal agencies until 27 September to deal with it. Anyone still running an unpatched WSO2 API Manager, API Control Plane, Traffic Manager or Universal Gateway should assume the patch gap is now being used.

The bug is simple to state. WSO2's JWT authentication accepts a token signed with an algorithm it does not support, and then treats that token as valid. An attacker writes their own token, sets an unsupported algorithm, fills in whatever claims they like, and gets in. WSO2 scores it CVSS 10.0, or 9.8 in single-tenant deployments, and says it can lead to "full account takeover", administrative accounts included.


What happened

WSO2 published security advisory WSO2-2026-5328 on 3 May 2026. Its summary: "JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access." The flaw was reported by the Hacktron Team. (SecurityWeek dates the fix to April; the advisory itself is dated 3 May.)

The CVE record followed on 6 August, when NVD published CVE-2026-5430. It classes the bug as CWE-347, improper verification of a cryptographic signature, with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H: network-reachable, low complexity, no credentials, no user interaction. No technical write-up or public exploit accompanied it.

That did not last. watchTowr's honeypots caught the first exploitation attempt on 13 September: a JWT carrying administrator privileges, sent to one of its research sensors. watchTowr then replayed that forged token against a vulnerable WSO2 deployment and bypassed authentication with it. The firm had already rebuilt the bug from WSO2's patch. SecurityWeek and The Hacker News reported the attacks on 16 September.

CISA listed CVE-2026-5430 in KEV on 24 September, with a due date of 27 September, three days later, and flagged it for forensic triage under BOD 26-04.

Data graphic: attack path for CVE-2026-5430, CVSS 10.0. A forged admin JWT with an unsupported algorithm is accepted by the WSO2 JWT check, giving admin access and then API keys and secrets. No credentials are needed; API Manager 4.6.0 is fixed in Update 21.

How a forged token becomes an admin session: the JWT check accepts an algorithm it does not support. Rotate secrets if the deployment was exposed while unpatched.

Why a forged token is so damaging here

An API manager is where an organisation keeps the keys to its other systems. According to the reporting on watchTowr's findings, a forged admin token gives access to API backend endpoints, credentials, and the consumer keys and secrets of every registered application. Those secrets keep working after the gateway is patched. So a deployment that was exposed between May and the day it was updated may already have leaked credentials that need rotating, even though the hole itself is now closed.

WSO2 has nearly 1,000 enterprise customers, according to SecurityWeek, concentrated in banking, government, telecoms and logistics.

CISA's entry describes a different bug

The KEV entry for CVE-2026-5430 does not match the vulnerability. CISA names it "WSO2 Multiple Products Path Traversal Vulnerability" and describes "a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution." That wording is still in the catalog as of its 1 October release.

WSO2's advisory and the NVD record both describe a JWT algorithm bypass and nothing about file upload. The KEV entry's own weakness field agrees with them: it lists CWE-347, the signature-verification class, not a path traversal CWE. The file-upload wording reads like WSO2's earlier KEV entry, CVE-2022-29464 ("unrestricted file upload, resulting in remote code execution"). TF treats the vendor and NVD description as correct and the KEV text as an error.

Data graphic: CISA's KEV entry calls CVE-2026-5430 a path traversal leading to file upload and RCE, while WSO2 and NVD describe a JWT bypass leading to admin takeover. Both list weakness CWE-347.

The KEV entry's name and description do not match the vendor advisory or the NVD record; its CWE-347 does. Triage from WSO2's advisory.

It matters for one practical reason. A team triaging from the KEV feed alone may go hunting for uploaded web shells and path-traversal requests, and miss the forged-token logins and stolen API secrets that this bug actually produces. The CVE ID, the affected products and the remediation link in the entry are all correct; only the name and description are wrong.

Affected products and fixed versions

ProductAffectedFixed at update level
API Manager4.1.0 to 4.6.04.1.0 U257, 4.2.0 U197, 4.3.0 U108, 4.4.0 U72, 4.5.0 U57, 4.6.0 U21
API Control Plane4.5.0, 4.6.04.5.0 U58, 4.6.0 U22
Traffic Manager4.5.0, 4.6.04.5.0 U56, 4.6.0 U21
Universal Gateway4.5.0, 4.6.04.5.0 U57, 4.6.0 U21

Update levels are taken from the NVD record's version ranges. NVD marks API Manager releases before 4.1.0 as "unknown" rather than unaffected.

Open-source users without a WSO2 subscription get no update levels. WSO2 points them to two pull requests instead, #13752 in carbon-apimgt and #14167 in product-apim, or to an upgrade to a fixed release.

What defenders should do

  1. Patch now to the update level above for each product and version, or apply the two pull requests on open-source builds.
  2. Take management interfaces off the internet, or restrict them to known administrative networks.
  3. Hunt for forged tokens. Review authentication logs from May onward for JWTs with unexpected alg values and for administrator sessions you cannot account for.
  4. Check for changes. Look over API definitions, applications and gateway configuration for edits nobody made on purpose.
  5. Rotate secrets if the deployment was exposed while unpatched: consumer keys and secrets, backend credentials, and service-account tokens held in the platform.
  6. Do not triage from the KEV text. Use WSO2's advisory for what to look for, not the path-traversal description.

Sources

Keep reading

All latest →
  1. criticalExploitsCheck Point Management Servers Were a Zero-Day for Two Months Before the Fix6 min
  2. criticalExploitsCisco SD-WAN Manager Zero-Day CVE-2026-76504: One Encoded Character Unlocks the Admin API5 min
  3. criticalExploitsExploited FortiMail Flaw Has No Patch Yet: Disable IBE Now5 min
  4. criticalExploitsCitrix NetScaler Zero-Days Planted Webshells Weeks Before the Patch8 min
  5. criticalExploitsUnder Active Attack: Cisco ISE Zero-Day (CVE-2026-76460) Grants Remote Unauthenticated Admin Access8 min
  6. criticalExploitsShieldCrash Zero-Day Analysis: Bypassing Microsoft Defender's ShieldBreak Fix (CVE-2026-69414) for Arbitrary SYSTEM File Reads7 min