CVE-2026-5430
CVSS 10 CRITICAL: the JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. EPSS 0.2% (13th percentile).
Vulnerabilities · 4h ago
WatchTowr says attackers are actively exploiting CVE-2026-5430, a critical WSO2 JWT authentication bypass patched in April, and that its honeypots saw the first attempt on September 13. The flaw affects WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway, which sit in front of APIs for banking, government, telecom, and logistics environments.
The bug is in token validation: WSO2 is supposed to reject JWTs signed with an unsupported algorithm, but a forged token can still be accepted. Once that happens, the attacker is treated as authenticated, and WatchTowr says the token can expose consumer keys, secrets, and access to backend API endpoints and internal services.
That makes the blast radius larger than the gateway itself. If a WSO2 deployment fronts sensitive APIs, a successful bypass can hand over the credentials and trust paths the gateway was meant to protect, and WatchTowr’s replay of the payload on the real product suggests abuse can be turned into working exploit code quickly.
CVSS 10 CRITICAL: the JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. EPSS 0.2% (13th percentile).
1 source covering this story
Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data.
Part of the PlainSec briefing for 2026-09-16