CVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Record summary
CVE-2026-5430 has a selected CVSS score of 10.0 (critical).
Description
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
WSO2 API Control PlaneBrowse WSO2 / WSO2 API Control PlaneDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.58 | affected |
| 4.6.0 to < 4.6.0.22 | affected | ||
WSO2 API ManagerBrowse WSO2 / WSO2 API ManagerDefault status: unaffected | CVE List | Before 4.1.0 | unknown |
| 4.1.0 to < 4.1.0.257 | affected | ||
| 4.2.0 to < 4.2.0.197 | affected | ||
| 4.3.0 to < 4.3.0.108 | affected | ||
| 4.4.0 to < 4.4.0.72 | affected | ||
| 4.5.0 to < 4.5.0.57 | affected | ||
| 4.6.0 to < 4.6.0.21 | affected | ||
WSO2 Carbon API Manager Rest API UtilityBrowse WSO2 / WSO2 Carbon API Manager Rest API Utilityorg.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.utilDefault status: unknown | CVE List | 9.20.74 to < 9.20.74.401 | affected |
| 9.28.116 to < 9.28.116.417 | affected | ||
| 9.29.120 to < 9.29.120.236 | affected | ||
| 9.30.67 to < 9.30.67.167 | affected | ||
| 9.31.86 to < 9.31.86.158 | affected | ||
| 9.32.147 to < 9.32.147.59 | affected | ||
| 9.33.106 to ≤ * | unaffected | ||
WSO2 Traffic ManagerBrowse WSO2 / WSO2 Traffic ManagerDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.56 | affected |
| 4.6.0 to < 4.6.0.21 | affected | ||
WSO2 Universal GatewayBrowse WSO2 / WSO2 Universal GatewayDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.57 | affected |
| 4.6.0 to < 4.6.0.21 | affected |