CVE-2026-5430
WSO2 JWT authentication bypass allows unauthenticated account takeover (CVE-2026-5430)
Several WSO2 API products accept JWTs signed with unapproved algorithms, allowing unauthenticated attackers to take over accounts. CISA KEV lists CVE-2026-5430 as actively exploited with a 2026-09-27 due date; patched builds are available.
What happened
An authentication flaw in multiple WSO2 API management and gateway products allows an attacker to craft a JSON Web Token (JWT) signed with an algorithm that is not among those the product is configured to support, and have the token accepted anyway. The vulnerability is reachable over the network, requires no privileges and no user interaction, and has low attack complexity. The CVE record scores it 10 (critical) with a changed scope; in single-tenant deployments the score adjusts to 9.8 because the impact is confined to a single security authority boundary. Successful exploitation may grant unauthorized access, including compromise of administrative accounts and full account takeover. CISA KEV and CISA SSVC record exploitation as active.
Who is affected
Affected products and versions:
- WSO2 Universal Gateway 4.5.0 to before 4.5.0.57 and 4.6.0 to before 4.6.0.21
- WSO2 Traffic Manager 4.5.0 to before 4.5.0.56 and 4.6.0 to before 4.6.0.21
- WSO2 API Control Plane 4.5.0 to before 4.5.0.58 and 4.6.0 to before 4.6.0.22
- WSO2 API Manager 4.1.0 to before 4.1.0.257, 4.2.0 to before 4.2.0.197, 4.3.0 to before 4.3.0.108, 4.4.0 to before 4.4.0.72, 4.5.0 to before 4.5.0.57, and 4.6.0 to before 4.6.0.21
- WSO2 Carbon API Manager Rest API Utility 9.20.74 to before 9.20.74.401, 9.28.116 to before 9.28.116.417, 9.29.120 to before 9.29.120.236, 9.30.67 to before 9.30.67.167, 9.31.86 to before 9.31.86.158, and 9.32.147 to before 9.32.147.59
The affected components provide API management, gateway, traffic management and control plane functions, so network reachability is the key exposure factor.
What to do now
- Identify whether any of the affected WSO2 products and versions listed above are in use, including in cloud or managed deployments.
- Apply the vendor's fixed builds. For Universal Gateway use 4.5.0.57 or 4.6.0.21. For Traffic Manager use 4.5.0.56 or 4.6.0.21. For API Control Plane use 4.5.0.58 or 4.6.0.22. For API Manager use 4.1.0.257, 4.2.0.197, 4.3.0.108, 4.4.0.72, 4.5.0.57 or 4.6.0.21. For Carbon API Manager Rest API Utility use 9.20.74.401, 9.28.116.417, 9.29.120.236, 9.30.67.167, 9.31.86.158 or 9.32.147.59.
- Treat CISA KEV's due date of 2026-09-27 as the deadline. For any asset that cannot be patched by then, evaluate its internet exposure. CISA's guidance for this entry is to apply vendor mitigations and, where mitigations are unavailable, discontinue use.
- While patching is in progress, restrict network access to affected WSO2 components to trusted networks and review authentication activity for administrative accounts.
How to detect it
Review JWT authentication logs for tokens whose algorithm (alg) claim is not among those your WSO2 deployment is configured to accept. Because the flaw is reachable without credentials, also identify any affected WSO2 components that are reachable from the internet or untrusted segments.
Beyond the patch
An actively exploited, network-reachable authentication bypass makes the patch urgent, but it also means the post-patch question is what else is exposed the same way. Managed Detection & Response (MDR) can monitor for the administrative or API activity that follows account takeover, and Virtual CISO Services (vCISO) can help you map and reduce the internet exposure of WSO2 components before the next CVE reaches the KEV list.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| WSO2 Universal Gateway | 4.5.0 – < 4.5.0.57 4.6.0 – < 4.6.0.21 | 4.5.0.57 4.6.0.21 |
| WSO2 Traffic Manager | 4.5.0 – < 4.5.0.56 4.6.0 – < 4.6.0.21 | 4.5.0.56 4.6.0.21 |
| WSO2 API Control Plane | 4.5.0 – < 4.5.0.58 4.6.0 – < 4.6.0.22 | 4.5.0.58 4.6.0.22 |
| WSO2 API Manager | 4.1.0 – < 4.1.0.257 4.2.0 – < 4.2.0.197 4.3.0 – < 4.3.0.108 4.4.0 – < 4.4.0.72 4.5.0 – < 4.5.0.57 4.6.0 – < 4.6.0.21 | 4.1.0.257 4.2.0.197 4.3.0.108 4.4.0.72 4.5.0.57 4.6.0.21 |
| WSO2 Carbon API Manager Rest API Utility | 9.20.74 – < 9.20.74.401 9.28.116 – < 9.28.116.417 9.29.120 – < 9.29.120.236 9.30.67 – < 9.30.67.167 9.31.86 – < 9.31.86.158 9.32.147 – < 9.32.147.59 | 9.20.74.401 9.28.116.417 9.29.120.236 9.30.67.167 9.31.86.158 9.32.147.59 |