
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5430 is a critical JWT authentication bypass vulnerability affecting multiple WSO2 products, classified as "Improper Verification of Cryptographic Signature" (CWE-347). The flaw allows unauthenticated attackers to craft JWT tokens using unsupported or unexpected signing algorithms that are incorrectly accepted by the authentication mechanism, leading to unauthorized access and full account takeover. Affected products include WSO2 API Manager (versions 4.1.0–4.6.x), WSO2 Traffic Manager (4.5.0–4.6.x), WSO2 Universal Gateway (4.5.0–4.6.x), and WSO2 API Control Plane (4.5.0–4.6.x), as well as the underlying org.wso2.carbon.apimgt.rest.api.util library across multiple versions. The vulnerability was published on August 6, 2026, with a CVSS v3.1 base score of 10.0 (Critical) in multi-tenant deployments, adjusted to 9.8 (Critical) in single-tenant deployments (GitHub Advisory, WSO2 Advisory).
The root cause is CWE-347 (Improper Verification of Cryptographic Signature): the JWT validation logic in WSO2's REST API utility does not enforce a strict allowlist of permitted signing algorithms, accepting tokens signed with algorithms outside those explicitly configured or supported. An attacker can exploit this by crafting a JWT with an unexpected or weak algorithm (e.g., none, or an algorithm not in the configured set), which the server then incorrectly validates as legitimate. This attack requires no prior authentication, no user interaction, and is exploitable remotely over the network. The vulnerability maps to CAPEC-475 (Signature Spoofing by Improper Validation) (GitHub Advisory, WSO2 Advisory).
Successful exploitation grants an unauthenticated attacker full unauthorized access to the affected WSO2 system, including the ability to compromise administrative accounts and perform complete account takeover across all users. The impact spans confidentiality, integrity, and availability — an attacker can read sensitive API management data, modify configurations or API policies, and potentially disrupt service operations. In multi-tenant deployments, the scope is changed (CVSS S:C), meaning exploitation in one tenant context could affect resources across security boundaries (GitHub Advisory, WSO2 Advisory).
As of the time of publication, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is rated automatable (no user interaction required) with low attack complexity, making it highly attractive for opportunistic attackers once exploitation techniques become public. The EPSS score is approximately 0.22% (13th percentile), indicating a currently low but non-negligible probability of exploitation within 30 days. No threat actor attribution or CISA KEV catalog listing has been reported at this time (GitHub Advisory).
none, a weak symmetric algorithm, or an entirely unsupported algorithm. Tools like jwt_tool or custom scripts can facilitate this./api/am/admin/v4/ or similar) with the crafted JWT in the Authorization: Bearer header./api/am/admin/, /api/am/publisher/, /api/am/devportal/) from unfamiliar source IPs; requests with Authorization: Bearer headers containing JWTs using unusual or none algorithms.deployment.toml, api-manager.xml) that could indicate post-exploitation persistence attempts.WSO2 has released patched versions addressing this vulnerability. Organizations should upgrade to the following fixed builds as soon as possible:
org.wso2.carbon.apimgt.rest.api.util library: 9.20.74.401, 9.28.116.417, 9.29.120.236, 9.30.67.167, 9.31.86.158, 9.32.147.59As a configuration-based workaround where immediate patching is not possible, enforce strict JWT algorithm validation to reject any tokens not signed with explicitly whitelisted algorithms, and implement network-level access controls to restrict exposure of WSO2 management APIs to trusted networks only (WSO2 Advisory, GitHub Advisory).
The vulnerability received coverage from security news outlets including SecurityOnline.info, which published articles on WSO2 API Manager vulnerabilities and account takeover flaws shortly after disclosure. Community discussion appeared on Reddit's r/pwnhub CVE daily brief for August 6, 2026, and the vulnerability was noted on Mastodon/infosec.exchange by threat intelligence accounts. Multiple vulnerability aggregation platforms (VulnDB, CVEFeed, CIRCL, INCIBE) indexed the advisory promptly, reflecting the high severity rating. No major vendor statements beyond WSO2's own advisory or notable independent researcher deep-dives have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."