Vulnerability threat dossier

CVE-2026-5430

wso2api control plane

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

VTP deterministic threat20.6of 100 · CVSS excluded

VTP analyst assessment

WSO2 JWT validation bypass reportedly exploited

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence72%
Public exploitation · VTP factREPORTED

Assessment

SecurityWeek and The Hacker News report exploitation attempts against CVE-2026-5430. The JWT mechanism accepts unsupported signing algorithms, allowing forged tokens to be incorrectly validated and potentially grant unauthorized or administrative access.

Why it matters

  • WSO2 API components may trust forged JWTs at an authentication boundary.
  • An attacker who bypasses token validation could access enterprise data or administrative functions.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The available reporting is press coverage with unknown source independence.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use WSO2 API Control Plane, API Manager, or Traffic Manager, apply the vendor remediation urgently.

AI baseline history (2)
  1. BASELINE ASSESSED
    WSO2 JWT validation bypass reportedly exploitedgpt-5.6-terra · low
  2. BASELINE ASSESSED
    WSO2 API Manager JWT bypass exploitation reportedgpt-5.6-terra · low
Technical severityCRITICALCVSS 10.0 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0025th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.00; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:a54e42a7a70c16f08a16c41272759fead2402a3691059914a299f1dff37581fcACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:31fd706486f027b1cffef08992f56cdea5df77d89ebce97a284db1781dba4a9cACTIVE
Evidence
04

Event history

Threat timeline

  1. 08:3916 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 05:1816 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek .

CVE-2026-5430
Separate evidence group
Original

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication

CVE-2026-5430
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score20.6vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.06 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
10 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-347
CPE records
4
Deterministic history records
8
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.