ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

Active Attacks Exploit WSO2 JWT Authentication Bypass CVE-2026-5430 With Forged Admin Tokens

criticalExploit / PoCexploited in the wildimportance 84CVE-2026-5430
What's new: New details beyond the previous summary: WSO2's advisory ID (WSO2-2026-5328); a CVSS of 9.8 for single-tenant deployments alongside the 10.0 score; product-specific affected version ranges (API Control Plane, Traffic Manager, and Universal Gateway 4.5.0-4.6.0, versus API Manager 4.1.0-4.6.0); a concrete fix example (API Manager 4.6.0 update 21) and migration to unaffected releases as a…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

WatchTowr honeypots captured the first exploitation attempts of CVE-2026-5430 (CVSS 10.0), a JWT authentication bypass in WSO2 API management products, on September 13, 2026, using forged tokens with baked-in administrator privileges that could expose API…

CVE-2026-5430 is an improper cryptographic signature verification flaw in WSO2 API management products that allows unauthenticated attackers to bypass JWT authentication by supplying tokens signed with unsupported algorithms, enabling full administrative account takeover. WSO2 disclosed the flaw in advisory WSO2-2026-5328, assigning CVSS 10.0 (9.8 for single-tenant deployments; watchTowr cites a range of 9.8-10.0), with a vector indicating remote exploitation requiring no credentials or user interaction. Affected products are WSO2 API Manager 4.1.0-4.6.0, API Control Plane 4.5.0-4.6.0, Traffic Manager 4.5.0-4.6.0, and Universal Gateway 4.5.0-4.6.0; the WSO2 platform serves nearly 1,000 enterprise customers in banking, government, telecom, and logistics. On September 13, 2026, WatchTowr honeypots captured forged JWT tokens carrying administrator privileges — the first exploitation attempt, roughly two months after the CVE record was published in early August 2026. The flaw was patched by WSO2 in April 2026 with an advisory in May. Successful exploitation could expose backend endpoint credentials, consumer keys, and secrets for every registered application, and compromise of the API control plane can expose managed APIs, policies, and backend services. Fixes are available via GitHub pull requests, subscription update levels (e.g., API Manager 4.6.0 update 21), or by migrating to unaffected releases. Users are urged to patch immediately.

  • CVE-2026-5430: JWT authentication bypass via tokens signed with unsupported algorithms, enabling unauthenticated admin account takeover
  • CVSS 10.0 per WSO2 advisory WSO2-2026-5328; 9.8 for single-tenant deployments; watchTowr cites a range of 9.8-10.0
  • CVSS vector indicates remote exploitation with no credentials or user interaction required
  • WatchTowr honeypots observed the first exploitation attempt on September 13, 2026, capturing forged JWT tokens with baked-in administrator privileges
  • Exploitation could expose backend endpoint credentials, consumer keys, and secrets for every registered application; control plane compromise can expose managed APIs, policies, and backend services
  • Affected products: WSO2 API Manager 4.1.0-4.6.0, API Control Plane 4.5.0-4.6.0, Traffic Manager 4.5.0-4.6.0, and Universal Gateway 4.5.0-4.6.0
  • WSO2 patched the flaw in April 2026 with an advisory in May; the CVE record was published in early August 2026
  • Fixes available via GitHub pull requests, subscription update levels (e.g., API Manager 4.6.0 update 21), or migration to unaffected releases

Coverage timeline

  1. · 13h ago
    The Hacker News· 78
    Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

    watchTowr observed active exploitation of CVE-2026-5430, a WSO2 API Manager JWT bypass using forged admin tokens, risking credential theft and account takeover.

  2. · 10h ago
    SecurityWeek· 84
    Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

    Attackers are actively exploiting CVE-2026-5430 (CVSS 10), a WSO2 JWT authentication bypass, to access enterprise API credentials and sensitive data.

  3. · 3h ago
    Cyber Security News· 65
    Critical WSO2 Vulnerability Allow Hackers to Gain Full Admin Access

    WSO2 discloses CVE-2026-5430 (CVSS 10.0), an unauthenticated JWT authentication bypass allowing admin account takeover across its API management products.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-5430
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported.

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

NVD description · AI analysis pending
10.0<1%
  • wso2 api control plane
  • wso2 api manager
  • wso2 traffic manager
  • +1 more