ZeroHour
Cyber Security Newspublished ()ingested Abinaya
Part of a story covered by 3 sources: “Active Attacks Exploit WSO2 JWT Authentication Bypass CVE-2026-5430 With Forged Admin Tokens” — merged summary and timeline →

Critical WSO2 Vulnerability Allow Hackers to Gain Full Admin Access

AI summary · glm-5.3-flash

WSO2 discloses CVE-2026-5430 (CVSS 10.0), an unauthenticated JWT authentication bypass allowing admin account takeover across its API management products.

WSO2 disclosed CVE-2026-5430, a critical authentication bypass (CVSS 10.0; 9.8 for single-tenant deployments) in advisory WSO2-2026-5328. The flaw stems from insecure JWT processing: tokens signed with unsupported algorithms bypass authentication checks, potentially granting unauthenticated attackers administrative access. Affected products include WSO2 API Control Plane 4.5.0-4.6.0, API Manager 4.1.0-4.6.0, Traffic Manager 4.5.0-4.6.0, and Universal Gateway 4.5.0-4.6.0. Fixes are available via update levels such as API Manager 4.6.0 update 21 or by migrating to unaffected releases.

  • JWT authentication can be bypassed by supplying a token signed with an unsupported algorithm
  • Affects API Control Plane, API Manager, Traffic Manager, and Universal Gateway versions 4.1.0-4.6.0
  • CVSS 10.0 vector shows remote exploitation with no credentials or user interaction
  • Compromise of the API control plane can expose managed APIs, policies, and backend services
  • Fixes shipped via update levels, e.g. API Manager 4.6.0 update 21

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-5430
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported.

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

NVD description · AI analysis pending
10.0<1%
  • wso2 api control plane
  • wso2 api manager
  • wso2 traffic manager
  • +1 more
Full article469 words · extracted from cybersecuritynews.com · click to collapse

WSO2 has disclosed a critical authentication bypass vulnerability that could allow remote attackers to take over accounts, including administrative accounts, in affected API management products.

Tracked as CVE-2026-5430, the flaw has received a CVSS score of 10.0 and requires no authentication or user interaction to exploit.

Security Advisory WSO2-2026-5328 details the issue, published on May 3, 2026. It affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway deployments across several currently supported product versions.

CVE-2026-5430 exists because affected WSO2 products process JSON Web Token authentication in an insecure way. According to WSO2, JWT authentication can be bypassed when an attacker supplies a token signed with an unsupported algorithm.

This condition may allow an unauthenticated attacker to bypass normal authentication checks and gain access to protected application functions.

A successful attack could lead to unauthorized access to API management environments, compromise of privileged user accounts, and complete account takeover.

Since API management platforms often control API publication, gateway routing, developer access, subscriptions, authentication settings, and backend service integrations, the impact could extend beyond the WSO2 deployment itself.

WSO2 Vulnerability

An attacker who obtains administrative access may be able to alter API configurations, create unauthorized users, modify access policies, change API endpoints, or access sensitive data exposed through managed APIs.

In enterprise environments, a compromised API control plane may also enable attackers to interfere with internal services and cloud-connected workloads.

WSO2 assigned the flaw a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, reflecting that it can be exploited remotely with low complexity, without credentials or user interaction.

The vendor noted that the score is adjusted to 9.8 for single-tenant deployments because the security impact is limited to one security authority boundary.

Affected versions include WSO2 API Control Plane 4.6.0 and 4.5.0; WSO2 API Manager versions 4.1.0 through 4.6.0; WSO2 Traffic Manager 4.5.0 and 4.6.0; and WSO2 Universal Gateway 4.5.0 and 4.6.0.

WSO2 has released fixes for open-source users through public code changes in the Carbon API Management and Product APIM repositories. Organizations that cannot immediately apply the fixes should migrate to the latest unaffected release of the relevant product.

Customers with WSO2 support subscriptions should apply the vendor-provided update levels or newer updates. The required levels include API Manager 4.6.0 update 21, 4.5.0 update 57, 4.4.0 update 72, 4.3.0 update 108, 4.2.0 update 197, and 4.1.0 update 257.

Security teams should identify internet-exposed WSO2 instances, prioritize patching, review administrator account activity, and inspect authentication logs for suspicious JWT validation events. WSO2 credited the Hacktron Team for responsibly reporting the vulnerability.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/critical-wso2-vulnerability/