Record summary

CVE-2026-5430 has a selected CVSS score of 10.0 (critical).

Description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.5.0 to < 4.5.0.58affected
4.6.0 to < 4.6.0.22affected

Default status: unaffected

CVE ListBefore 4.1.0unknown
4.1.0 to < 4.1.0.257affected
4.2.0 to < 4.2.0.197affected
4.3.0 to < 4.3.0.108affected
4.4.0 to < 4.4.0.72affected
4.5.0 to < 4.5.0.57affected
4.6.0 to < 4.6.0.21affected

WSO2 Carbon API Manager Rest API Utility

Browse WSO2 / WSO2 Carbon API Manager Rest API Utilityorg.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util

Default status: unknown

CVE List9.20.74 to < 9.20.74.401affected
9.28.116 to < 9.28.116.417affected
9.29.120 to < 9.29.120.236affected
9.30.67 to < 9.30.67.167affected
9.31.86 to < 9.31.86.158affected
9.32.147 to < 9.32.147.59affected
9.33.106 to ≤ *unaffected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.56affected
4.6.0 to < 4.6.0.21affected

Default status: unaffected

CVE List4.5.0 to < 4.5.0.57affected
4.6.0 to < 4.6.0.21affected

References

2