CISA Flags WSO2 Security Flaw Under Active Exploitation
CISA added actively exploited WSO2 flaw CVE-2026-5430, a CVSS 10 path traversal and JWT bug, to KEV.
CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on September 24, 2026, after evidence of active exploitation, and set a federal remediation deadline of September 27. The flaw affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. CISA describes a path traversal issue that can allow unrestricted file uploads and remote code execution. The CVE record also cites improper JWT signature verification, CWE-347, that can enable crafted tokens, administrative compromise, and full account takeover, with a CVSS v3.1 score of 10.0 in one scenario. Ransomware use is unknown, but BOD 26-04 requires forensic triage.
- CVE-2026-5430 entered CISA KEV with a September 27 federal deadline.
- Path traversal may allow unrestricted uploads and remote code execution.
- A JWT validation weakness can lead to administrative account takeover.
- One CVSS v3.1 scenario scores 10.0; ransomware use is unknown.
- BOD 26-04 requires forensic triage, not patching alone.
Vulnerabilities mentionedAll →
- CVE-2026-543010.0<1%Unauthenticated JWT Algorithm Bypass in WSO2 API Manager and Gatewayspublished · wso2 api manager KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-5430 |
Full article517 words · extracted from gbhackers.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting WSO2, tracked as CVE-2026-5430, to its Known Exploited Vulnerabilities (KEV) catalog.
CISA made this decision after evidence showed threat actors are actively exploiting the flaw. CISA added the vulnerability on September 24, 2026, and set a remediation deadline for affected federal civilian agencies by September 27.
CVE-2026-5430 impacts several WSO2 products, including the WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway.
CISA describes this issue as a path traversal vulnerability that may allow unrestricted file uploads, potentially leading to remote code execution on vulnerable systems.
This vulnerability is particularly severe because WSO2 deployments often operate in front of business-critical APIs, authentication services, and application traffic.
A successful exploit could provide an attacker with a foothold in an organization’s API management environment, enabling them to steal sensitive data, manipulate API traffic, deploy malicious payloads, or move laterally into connected systems.
WSO2 Security Flaw
The CVE record indicates a weakness in the JWT authentication mechanism, where affected products may accept tokens signed with algorithms not explicitly configured or supported by administrators. An attacker could potentially craft a token using an unsupported algorithm that is improperly validated, leading to unauthorized access.
The vendor record warns that exploiting this vulnerability can compromise administrative accounts and lead to full account takeovers.
The vulnerability has received a maximum CVSS v3.1 score of 10.0 under one scoring scenario, indicating its network-reachable nature, low attack complexity, lack of required privileges or user interaction, and potentially severe impact on confidentiality, integrity, and availability.
CWE information associated with this CVE identifies CWE-347, which concerns improper verification of cryptographic signatures. This classification aligns with the JWT-validation component of the vulnerability, and organizations should evaluate both the authentication weaknesses and file upload vulnerabilities described in the advisory.
CISA’s KEV entry states that ransomware use is currently unknown; however, the agency has marked this vulnerability as requiring forensic triage under Binding Operational Directive 26-04. This means that affected organizations should not treat patching as the only necessary response.
Federal agencies are required to apply vendor-recommended mitigations and follow the risk-based update guidance outlined in BOD 26-04. CISA also instructs stakeholders to assess the internet exposure of each affected asset, comply with relevant cloud service requirements, and discontinue the use of products for which effective mitigations are not available.
Security teams should immediately identify any internet-facing WSO2 instances, determine the deployed versions and roles, and review access logs for unusual file uploads, suspicious JWT activity, unexpected administrator account creation, and anomalous API gateway behavior.
Additionally, teams should rotate any potentially exposed credentials, review API access tokens, and investigate systems for web shells or unauthorized configuration changes.
WSO2 has published a vendor security advisory for CVE-2026-5430, and organizations are encouraged to follow the remediation instructions provided in that advisory.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.