CVE-2026-5430 Details
Description
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
A vulnerability exists in the JWT authentication mechanism of multiple WSO2 products, including WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, all in versions 4.6.0 and 4.5.0. This vulnerability allows an attacker to bypass authentication by crafting a JWT signed with an unsupported algorithm, which is then incorrectly validated. Exploitation of this flaw could result in unauthorized access to the system, potentially compromising administrative accounts and leading to full account takeover.
Community users can apply the relevant fixes available on GitHub for WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. Support subscription holders should update to the specified update level or a higher version to mitigate the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-5430 | CISA-ADP | US Government Resource |
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/ | WSO2 LLC | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| WSO2 Multiple Products Path Traversal Vulnerability | Sep 24, 2026 | Sep 27, 2026 | Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | WSO2 LLC |
Affected Products
| Product | Versions |
|---|---|
| wso2 api control plane | >= 4.5.0, < 4.5.0.58 >= 4.6.0, < 4.6.0.22 |
CPE
Remediation
| |
| wso2 api manager | >= 4.1.0, < 4.1.0.257 >= 4.2.0, < 4.2.0.197 >= 4.3.0, < 4.3.0.108 >= 4.4.0, < 4.4.0.72 >= 4.5.0, < 4.5.0.57 >= 4.6.0, < 4.6.0.21 |
CPE
Remediation
| |
| wso2 traffic manager | >= 4.5.0, < 4.5.0.56 >= 4.6.0, < 4.6.0.21 |
CPE
Remediation
| |
| wso2 universal gateway | >= 4.5.0, < 4.5.0.57 >= 4.6.0, < 4.6.0.21 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | Modified Analysis | [email protected] |
| Sep 25, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | CVE Modified | WSO2 LLC |
| Aug 10, 2026 | Initial Analysis | [email protected] |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | WSO2 LLC |