CVE-2026-5430: critical vulnerability in WSO2 API Control Plane
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
A flaw in JWT token validation allows attackers to bypass authentication by using unsupported algorithms, gaining unauthorized access to accounts including admin accounts without needing valid credentials.
The JWT validation mechanism fails to restrict token algorithms to explicitly configured ones (CWE-347), allowing an attacker to craft tokens with arbitrary algorithms that bypass signature verification. This network-accessible vulnerability requires no authentication or user interaction, resulting in complete compromise of confidentiality, integrity, and availability within affected tenants.
In the same product, most dangerous first.