Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-5430PATCHED
wso2 · api_control_plane

Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover

Description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

Affected Products

VendorProductVersions
wso2api_control_plane4.5.0, 4.6.0, 4.5.0, 4.6.0, 4.5.0, 4.6.0, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.5.0, 4.6.0, 9.20.74, 9.28.116, 9.29.120, 9.30.67, 9.31.86, 9.32.147

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
wso2universal_gatewaycve_cpe95%
wso2traffic_managercve_cpe95%
wso2api_managercve_cpe95%

References

  • https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/(vendor-advisory)

Related News (5 articles)

Tier D
BleepingComputer2d ago
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News2d ago
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
→ No new info (linked only)
Tier D
SecurityWeek11d ago
Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
→ No new info (linked only)
Tier D
The Hacker News11d ago
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
→ No new info (linked only)
Tier C
VulDB52d ago
CVE-2026-5430 | WSO2 API Control Plane improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.5.0.574.6.0.214.5.0.564.5.0.584.6.0.224.1.0.2574.2.0.1974.3.0.1084.4.0.729.20.74.4019.28.116.4179.29.120.2369.30.67.1679.31.86.1589.32.147.599.33.106
CWECWE-347
PublishedAug 6, 2026
Trending Score55
Source articles5
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2025-5802
Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery
Trending: 7
HIGHCVE-2026-19515
OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution
Trending: 7
LOWCVE-2025-13166
Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery
Trending: 4
MEDIUMCVE-2026-4103
Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution
Trending: 4
MEDIUMCVE-2026-3096
Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 6, 2026
Discovered by ZDM
Aug 6, 2026
Patch Available
Sep 25, 2026