CVE-2026-5430

Published Aug 6, 2026

Last updated 9 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-5430 is a signature verification vulnerability affecting WSO2 API management products, including API Control Plane, API Manager, Traffic Manager, and Universal Gateway. This flaw stems from the way these products handle JSON Web Token (JWT) authentication, specifically by accepting tokens signed with algorithms that are not explicitly configured or supported. An attacker can exploit this vulnerability by crafting a JWT signed with an unsupported algorithm, which the affected WSO2 products incorrectly validate as legitimate. This bypasses authentication mechanisms, potentially granting unauthorized access to the system, including administrative accounts.

Description
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD status
Analyzed
Products
api_control_plane, api_manager, traffic_manager, universal_gateway

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
WSO2 Multiple Products Path Traversal Vulnerability
Exploit added on
Sep 24, 2026
Exploit action due
Sep 27, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

ed10eef1-636d-4fbe-9993-6890dfa878f8
CWE-347

Social media

Hype score
Not currently trending
  1. CISA added two actively exploited bugs to its KEV catalog, patch deadline today. WSO2 API Manager (CVE-2026-5430): path traversal to RCE. Adobe Commerce/Magento (CVE-2026-71362): account takeover, no login needed. Patch now if you run either. https://t.co/odmR2nhSvE

    @NoDramaCyber

    27 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA's federal due date for WSO2 CVE-2026-5430 is today. KEV lists active exploitation; WSO2's advisory calls it JWT auth bypass that can take over admin accounts on API Manager and related products. Patch to the update levels in WSO2-2026-5328 if you still run those stacks.

    @arnavsharma

    27 Sept 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. WSO2 API Manager has a CVSS 10 auth bypass (CVE-2026-5430), and attackers have used forged admin tokens since Sep 13. The fix shipped in May. CISA added it to KEV Sep 24; the federal deadline is tomorrow, Sep 27. A JWT signed with an unsupported algorithm is accepted. https://t.

    @HardikDagha

    26 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🟠 𝗛𝗜𝗚𝗛 · 𝗗𝗶𝘀𝗰𝘂𝘀𝘀𝗶𝗼𝗻 🧩 Products: 𝗪𝗦𝗢𝟮 𝗔𝗣𝗜 𝗠𝗮𝗻𝗮𝗴𝗲𝗿, 𝗔𝗱𝗼𝗯𝗲 𝗖𝗼𝗺𝗺𝗲𝗿𝗰𝗲, 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗦𝗵𝗮𝗿𝗲𝗣𝗼𝗶𝗻𝘁 🛡

    @intels_daily

    26 Sept 2026

    122 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. WSO2 CVE-2026-5430 (CVSS 9.8): path traversal to unrestricted upload/RCE on API Manager & gateways. Actively exploited; CISA KEV due Sep 27. #cybersecurity #infosec #WSO2 #RCE #CVE https://t.co/jOyd4gXy7r

    @Caldura7

    26 Sept 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CISA added two actively exploited flaws to its KEV catalog: a WSO2 API Manager JWT bypass (CVE-2026-5430, CVSS up to 10.0) and an Adobe Commerce/Magento auth bypass (CVE-2026-71362, CVSS 9.1). Patches have been out since spring and August - if you run either product, check your

    @NoDramaCyber

    26 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. A KEV update turns two product flaws into a triage priority. CISA cites active exploitation; one is CVE-2026-5430, a 9.8 path-traversal flaw in WSO2. Inventory affected deployments and check official CISA and vendor guidance. Get the brief → https://t.co/veobY9kdyj https://t

    @SecBriefs

    26 Sept 2026

    164 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🔒 #CyberSecurity CVE-2026-5430: WSO2 Authentication Bypass Actively Exploited — Detection and Re… "The Cybersecurity and Infrastructure Security Agency (CISA) has added multiple…" 🔗 https://t.co/tZssgo5Jtf #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    @SecurityAr58409

    26 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CISA flags CVE-2026-5430 (WSO2) & CVE-2026-71362 (Adobe Commerce) as actively exploited – urgent patching needed to stop session‑hijack attacks on federal apps. #ThreatIntel #CyberSecurity https://t.co/0Rfr8lhlqS

    @Npj8448

    26 Sept 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. SecBoard Daily · 25 September 2026 Top story: CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks (CVE-2026-5430, actively exploited) 3 newly listed as exploited Full daily briefing on SecBoard – address in the image. #ThreatIntel #SharePoint https://

    @BytesNora

    26 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CISA added two actively exploited flaws to KEV: WSO2 CVE-2026-5430 (path traversal → RCE) and Adobe Commerce/Magento CVE-2026-71362. Federal deadline: Sept 27. Source: CISA + The Hacker News. Verify independently. #CyberSecurity #InfoSec #CVE #ThreatIntel #KEV

    @ThreatAlis

    26 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. TRC analysis shows attackers exploiting critical authentication bypass vulnerabilities in WSO2 API Manager (CVE-2026-5430) and Adobe Commerce (CVE-2026-71362) to compromise administrative accounts across banking and government sectors. Runtime segmentation helps limit blast

    @aviatrixtrc

    26 Sept 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 CTI ALERT | Sept 25, 2026: CISA adds WSO2 (CVE-2026-5430) & Adobe Commerce (CVE-2026-71362) to KEV following active in-the-wild exploitation. ​Threat actors are targeting identity/API management & e-commerce sessions. ​More in comments ⬇️ #Cybersecurity #Thre

    @ThreatIntebzqf

    25 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. CISA KEV yesterday: WSO2 CVE-2026-5430 + Magento CVE-2026-71362. Active exploit. Due Sep 27. WSO2: JWT auth bypass. Magento: unauth privilege escalation / session hijack. Run either? Patch now, then check for prior compromise. https://t.co/go2sKcueBY

    @bluefortit

    25 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 WSO2 CVE-2026-5430 — CVSS 10.0 JWT authentication bypass. Forged admin tokens → full access. ACTIVELY EXPLOITED — CISA KEV. Deadline: September 27. → https://t.co/MmxjOy1RTe #WSO2 #CVE #JWT #PatchNow #CyberSecurity #ThreatIntel

    @ThreatAft

    25 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. WSO2 Path Traversal and JWT Bypass Critical Vulnerability CVE-2026-5430 https://t.co/OWtx2ptLff via @YouTube Multiple Products - WSO2 Multiple Products Path Traversal Vulnerability Critical CVE-2026-5430 https://t.co/NTiB24eICu #CyberSecurity #MedCyber #ZeroTrust https://t.c

    @antibodycyber

    25 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. WSO2 Path Traversal and JWT Bypass Critical Vulnerability CVE-2026-5430 https://t.co/OWtx2ptLff via @YouTube Multiple Products - WSO2 Multiple Products Path Traversal Vulnerability Critical CVE-2026-5430 https://t.co/NTiB24eICu #CyberSecurity #MedCyber #ZeroTrust https://t.c

    @antibodycyber

    25 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CISA added CVE-2026-5430 (WSO2 CVSS 10.0 auth bypass) and CVE-2026-71362 (Adobe Commerce session hijack) to its KEV catalog under active exploitation. Patch perimeter assets immediately. Intel to https://t.co/MKs4bJKzie https://t.co/QC14eBVf0C

    @2Workly

    25 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🔒 #CyberSecurity CVE-2026-5430: WSO2 API Control Plane Path Traversal and Adobe Commerce Flaw Ad… "On Thursday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two…" 🔗 https://t.co/IuNb92smsv #CyberSecurity #ThreatIntel #cve #zeroday #patchtue

    @SecurityAr58409

    25 Sept 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. A perfect CVSS 10.0 in WSO2, now actively exploited. CVE-2026-5430 bypasses authentication entirely with a crafted JWT, no credentials needed. On CISA's KEV list, remediation due Sep 27. https://t.co/Uux2knHV3V #WSO2 #CVE #CyberSecurity #InfoSec

    @vuln_tracker

    25 Sept 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. A perfect CVSS 10.0 in WSO2 is now actively exploited and on CISA's KEV list. CVE-2026-5430 lets an attacker craft a JWT signed with an unsupported algorithm that gets validated anyway, bypassing authentication with zero credentials. It affects WSO2 API Control Plane, API https:

    @vuln_tracker

    25 Sept 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CISA added two actively exploited flaws to KEV: CVE-2026-5430 (WSO2 RCE) and CVE-2026-71362 (Adobe Commerce session hijack). Audit edge instances and patch now. Details: https://t.co/KQCYKm2f5S Intel to enforcement: https://t.co/QC14eBVf0C #2workly

    @2Workly

    25 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. #CISA 🔴 CISA añade fallos críticos de WSO2 y Adobe Commerce al catálogo KEV por explotación activa. ⚠️ Las vulnerabilidades CVE-2026-5430 y CVE-2026-71362 afectan a identidad y comercio. Las agencias deben parchar ya. https://t.co/V80X32YJnb via #TheHackerNews

    @renodevv

    25 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 【CISA KEV速報】2026-09-24付けで2件追加 ・CVE-2026-5430 WSO2 Multiple Products ・CVE-2026-71362 Adobe Commerce and Magento いずれも悪用確認済み。概要と対応期限はこちら https://t.co/um1SUocVPu

    @sec_news_com

    25 Sept 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. SecBoard Daily · 24 September 2026 Top story: CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-5430, actively exploited) 2 newly listed as exploited Full daily briefing on SecBoard – address in the image. #ThreatIntel https://t.co/tHnamyCIaV

    @BytesNora

    25 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CISA adds CVE-2026-71362 (@Adobe Commerce/Magento privilege escalation) and CVE-2026-5430 (WSO2 JWT bypass leading to RCE) to the KEV catalog after confirmed exploitation. Adobe issued guidance in August; WSO2 warned in May. Federal agencies must patch and investigate

    @WorldCyberNewsX

    25 Sept 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. CISA Adds Two Known Exploited Vulnerabilities to Catalog(CISA、悪用確認済み脆弱性2件をKEVカタログに追加) #CISA (Sep 24) CVE-2026-5430 WSO2 複数製品パストラバーサル脆弱性 CVE-2026-71362 Adob​​e CommerceおよびMagentoの認証エラ

    @foxbook

    25 Sept 2026

    204 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🔒 #CyberSecurity CVE-2026-5430 & CVE-2026-71362: CISA KEV Adds WSO2 Path Traversal and Adobe Com… "On September 24, 2026, CISA added two vulnerabilities to its Known Exploited…" 🔗 https://t.co/QSj0aOrfug #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    @SecurityAr58409

    25 Sept 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 🔒 #CyberSecurity CVE-2026-5430: WSO2 Path Traversal Under Active Exploitation — Detection and Re… "On September 24, 2026, CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/LwTFPR9HTM #CyberSecurity #ThreatIntel #cve20265430 #critical

    @SecurityAr58409

    25 Sept 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログにWSO2複数製品のCVE-2026-5430とAdobe Commerce/MagentoのCVE-2026-71362を追加。対処期限は3日後の9/27。ランサムウェアによる悪用は

    @__kokumoto

    25 Sept 2026

    574 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  31. CVSS 9.8. JWT bypass, no auth needed. CVE-2026-5430 in WSO2 API Manager lets attackers forge admin tokens. Active exploitation confirmed Sept. 13, 5 months post-patch. IOCs, Sigma rules, WAF configs: https://t.co/qf5AVkM2GG #WSO2 #CVE #CyberSecurity

    @DecryptionDigst

    18 Sept 2026

    28 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  32. 🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-22686 CVE-2026-5430 CVE-2026-86218 CVE-2026-12793 CVE-2026-12793 ..🧵👇

    @exploitgrid

    17 Sept 2026

    45 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  33. 🚨 WSO2 API Manager’da kritik açık! CVE-2026-5430, saldırganların hiçbir giriş yapmadan kimlik doğrulamayı aşmasına ve admin hesaplarını ele geçirmesine izin verebiliyor. CVSS skoru 10.0. WSO2 kullananların güncellemeleri kontrol etmesi önemli. #CyberSecu

    @KubbeSiber

    17 Sept 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 WSO2 API Manager’da kritik açık aktif sömürülüyor! CVE-2026-5430 (CVSS 9.8), saldırganların sahte admin token’ları oluşturarak JWT doğrulamasını aşmasına ve hesapları ele geçirmesine izin verebiliyor. Saldırılar gerçek sistemlerde gözlemlendi. #Cy

    @KubbeSiber

    16 Sept 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Gefälschte Admin-JWTs zielen auf ungepatchte WSO2-Systeme. CVE-2026-5430 ist ohne Benutzerkonto ausnutzbar. #WSO2 #CVE #JWT #Security https://t.co/LuYVJrQZTw

    @rohtext_de

    16 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🐦 🚨 Actively exploited: Cisco Secure Email Gateway CVE-2026-76461 (CVSS 9.8, CISA KEV) — unauth SQLi → root RCE via crafted email. Also in-the-wild: WSO2 API Manager CVE-2026-5430 (CVSS 9.8), JWT auth bypass → admin takeover. Patch both now. #infosec #CVE #0day

    @ita_ipo

    16 Sept 2026

    87 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨 WSO2 has patched four critical account takeover vulnerabilities, including CVE-2026-5430 (CVSS 10.0). The flaw allows authentication bypass via JWT, potentially leading to full account compromise. Users are urged to update immediately. #WSO2 #JWT #CVE #CyberSecurity

    @ThreatWire_

    7 Aug 2026

    642 Impressions

    0 Retweets

    9 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  38. 🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-11976 CVE-2026-14812 CVE-2026-5430 CVE-2026-65553 CVE-2026-66665 ..🧵👇

    @exploitgrid

    7 Aug 2026

    36 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  39. WSO2 patched four critical account takeover flaws, including CVE-2026-5430 at CVSS 10 via JWT auth bypass. Details and fixes inside. #WSO2 #AccountTakeover #CVE #APIsecurity #CyberSecurity https://t.co/pbUTKa9Owi

    @Daily_CyberSec

    7 Aug 2026

    414 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  40. NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 6 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱: 🔓 JWT accepted with an algorithm the server never configure

    @NewScanTeam

    6 Aug 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 🚨*CVE* CVE-2026-5430 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with … https://t.co/WePAaQe5Pt ----- Traducción: CVE-2026-5430 El … https://t.co/utmtNg

    @infoflowcloud

    6 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations