10

CVE-2026-5430

Warnung
Medienbericht

Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.

Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wso2 ≫ Api Control Plane Version >= 4.5.0 < 4.5.0.58
Wso2 ≫ Api Control Plane Version >= 4.6.0 < 4.6.0.22
Wso2 ≫ Api Manager Version >= 4.1.0 < 4.1.0.257
Wso2 ≫ Api Manager Version >= 4.2.0 < 4.2.0.197
Wso2 ≫ Api Manager Version >= 4.3.0 < 4.3.0.108
Wso2 ≫ Api Manager Version >= 4.4.0 < 4.4.0.72
Wso2 ≫ Api Manager Version >= 4.5.0 < 4.5.0.57
Wso2 ≫ Api Manager Version >= 4.6.0 < 4.6.0.21
Wso2 ≫ Traffic Manager Version >= 4.5.0 < 4.5.0.56
Wso2 ≫ Traffic Manager Version >= 4.6.0 < 4.6.0.21
Wso2 ≫ Universal Gateway Version >= 4.5.0 < 4.5.0.57
Wso2 ≫ Universal Gateway Version >= 4.6.0 < 4.6.0.21
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

24.09.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

WSO2 Multiple Products Path Traversal Vulnerability

Schwachstelle

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.129
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ed10eef1-636d-4fbe-9993-6890dfa878f8 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
25.09.2026 19:49
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
25.09.2026 08:48
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
16.09.2026 08:56
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-5430
US Government Resource