Active Attacks Exploit WSO2 JWT Authentication Bypass CVE-2026-5430 With Forged Admin Tokens
WatchTowr honeypots captured the first exploitation attempts of CVE-2026-5430 (CVSS 10.0), a JWT authentication bypass in WSO2 API management products, on September 13, 2026, using forged tokens with baked-in administrator privileges that could expose API…
CVE-2026-5430 is an improper cryptographic signature verification flaw in WSO2 API management products that allows unauthenticated attackers to bypass JWT authentication by supplying tokens signed with unsupported algorithms, enabling full administrative account takeover. WSO2 disclosed the flaw in advisory WSO2-2026-5328, assigning CVSS 10.0 (9.8 for single-tenant deployments; watchTowr cites a range of 9.8-10.0), with a vector indicating remote exploitation requiring no credentials or user interaction. Affected products are WSO2 API Manager 4.1.0-4.6.0, API Control Plane 4.5.0-4.6.0, Traffic Manager 4.5.0-4.6.0, and Universal Gateway 4.5.0-4.6.0; the WSO2 platform serves nearly 1,000 enterprise customers in banking, government, telecom, and logistics. On September 13, 2026, WatchTowr honeypots captured forged JWT tokens carrying administrator privileges — the first exploitation attempt, roughly two months after the CVE record was published in early August 2026. The flaw was patched by WSO2 in April 2026 with an advisory in May. Successful exploitation could expose backend endpoint credentials, consumer keys, and secrets for every registered application, and compromise of the API control plane can expose managed APIs, policies, and backend services. Fixes are available via GitHub pull requests, subscription update levels (e.g., API Manager 4.6.0 update 21), or by migrating to unaffected releases. Users are urged to patch immediately.
- CVE-2026-5430: JWT authentication bypass via tokens signed with unsupported algorithms, enabling unauthenticated admin account takeover
- CVSS 10.0 per WSO2 advisory WSO2-2026-5328; 9.8 for single-tenant deployments; watchTowr cites a range of 9.8-10.0
- CVSS vector indicates remote exploitation with no credentials or user interaction required
- WatchTowr honeypots observed the first exploitation attempt on September 13, 2026, capturing forged JWT tokens with baked-in administrator privileges
- Exploitation could expose backend endpoint credentials, consumer keys, and secrets for every registered application; control plane compromise can expose managed APIs, policies, and backend services
- Affected products: WSO2 API Manager 4.1.0-4.6.0, API Control Plane 4.5.0-4.6.0, Traffic Manager 4.5.0-4.6.0, and Universal Gateway 4.5.0-4.6.0
- WSO2 patched the flaw in April 2026 with an advisory in May; the CVE record was published in early August 2026
- Fixes available via GitHub pull requests, subscription update levels (e.g., API Manager 4.6.0 update 21), or migration to unaffected releases
Coverage timelineoldest first · each row is one article
- · 13h agoActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
The Hacker News· 78
watchTowr observed active exploitation of CVE-2026-5430, a WSO2 API Manager JWT bypass using forged admin tokens, risking credential theft and account takeover.
- · 10h agoEnterprises Warned of Attacks Exploiting WSO2 Vulnerability
SecurityWeek· 84
Attackers are actively exploiting CVE-2026-5430 (CVSS 10), a WSO2 JWT authentication bypass, to access enterprise API credentials and sensitive data.
- · 3h agoCritical WSO2 Vulnerability Allow Hackers to Gain Full Admin Access
Cyber Security News· 65
WSO2 discloses CVE-2026-5430 (CVSS 10.0), an unauthenticated JWT authentication bypass allowing admin account takeover across its API management products.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-5430 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary. NVD description · AI analysis pending | 10.0 | <1% |
| — |