CVE-2026-5430
CVSS 10 CRITICAL: the JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. EPSS 0.2% (13º percentile).
Vulnerabilità · 2 ore fa
WSO2 API Manager e i prodotti collegati di WSO2 sono finiti sotto tentativi di sfruttamento attivo per CVE-2026-5430, una falla che consente di presentare token JWT falsi con privilegi da amministratore. watchTowr riferisce di aver intercettato token forgiati il 13 settembre 2026, mentre WSO2 ha pubblicato la correzione per le versioni colpite.
Il problema è nella verifica della firma: il servizio accetta un JWT firmato con un algoritmo che dichiara di non supportare e lo tratta comunque come valido. In pratica, un attaccante può farsi passare per amministratore, riprendere il controllo della console e usare il gateway come punto di accesso ai backend, con esposizione di credenziali, consumer key e secret.
Per chi usa questi componenti davanti ad API interne o servizi condivisi, il rischio non resta confinato all’interfaccia del prodotto. Se l’accesso amministrativo è già stato ottenuto, il controllo del piano API può diventare un pivot verso sistemi e segreti a valle.
CVSS 10 CRITICAL: the JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. EPSS 0.2% (13º percentile).
1 fonte che coprono questa storia
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
WSO2 API Manager JWT bypass faces active exploitation attempts using forged tokens with administrator privileges.
Part of the PlainSec briefing for 2026-09-16