Vulnerability
Published 2026-09-16
Verified 2026-09-19

WSO2 API Manager JWT auth bypass CVE-2026-5430 (CVSS 9.8/10.0); active exploitation attempts (watchTowr)

WSO2 security advisory WSO2-2026-5328 / CVE-2026-5430 (published 3 May 2026; Critical): JWT authentication can be bypassed when a token is signed with an unsupported algorithm, allowing unauthorized access and potential administrative account takeover. Vendor CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); single-tenant deployments adjusted to 9.8 (S:U). Affected: WSO2 API Manager 4.1.0–4.6.0; API Control Plane 4.5.0/4.6.0; Traffic Manager 4.5.0/4.6.0; Universal Gateway 4.5.0/4.6.0. The Hacker News (16 September 2026) cites watchTowr honeypot telemetry capturing forged admin JWTs on 13 September 2026 — active in-the-wild exploitation attempts. Support subscription holders: apply stated update levels (e.g. API Manager 4.6.0 UL 21, 4.5.0 UL 57, 4.4.0 UL 72, 4.3.0 UL 108, 4.2.0 UL 197, 4.1.0 UL 257; Control Plane/Traffic Manager/Universal Gateway levels on the advisory). Community: GitHub fixes carbon-apimgt PR 13752 and product-apim PR 14167, or migrate to an unaffected release. Credits: Hacktron Team. Primary: WSO2 WSO2-2026-5328; wire: The Hacker News / watchTowr.

Product
WSO2 API Manager / API Control Plane / Traffic Manager / Universal Gateway
Versions
API Manager 4.1.0–4.6.0; API Control Plane 4.5.0–4.6.0; Traffic Manager 4.5.0–4.6.0; Universal Gateway 4.5.0–4.6.0
CVSS
(CVSS 3.1, WSO2 multi-tenant); 9.8 single-tenant
Exploited in Australia?
unknown
Patch to
Apply WSO2 Updates to advisory update levels (or higher); community: carbon-apimgt PR 13752 / product-apim PR 14167; or migrate to latest unaffected version; rotate exposed API credentials if compromise suspected

Primary: WSO2-2026-5328 / CVE-2026-5430 (vendor advisory) · Vendor: WSO2 Security Advisory · CVE: CVE-2026-5430 · The Hacker News — watchTowr active exploitation attempts (16 Sep 2026)

vulnerabilities cloud