Active Exploitation Alert: WSO2 API Manager / Gateway JWT Authentication Bypass — CVE-2026-5430 (WSO2-2026-5328) Added to CISA KEV

Active Exploitation Alert: WSO2 API Manager / Gateway JWT Authentication Bypass — CVE-2026-5430 (WSO2-2026-5328) Added to CISA KEV

Executive Summary

WSO2 API Manager and related gateway / control-plane products are under confirmed active exploitation for CVE-2026-5430 (vendor advisory WSO2-2026-5328), a JWT authentication bypass caused by improper verification of cryptographic signatures (CWE-347). Tokens signed with an unsupported algorithm can be incorrectly validated, enabling unauthorized access including administrative account takeover. WSO2 rates multi-tenant deployments CVSS 3.1 10.0 (Scope Changed) and single-tenant deployments 9.8.

CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on September 24, 2026 (due date September 27, 2026 for FCEB under BOD 26-04; known ransomware campaign use = Unknown; forensic triage = Yes). SecurityWeek, citing WatchTowr honeypot observations, reports first forged-admin JWT exploitation attempts around September 13, 2026.

Naming caveat: CISA KEV title and shortDescription currently use “Path Traversal” / file-upload→RCE language that conflicts with WSO2 and NVD (JWT authentication bypass, CWE-347). Prefer WSO2-2026-5328 and NVD for technical impact. KEV requiredAction still correctly points operators to the WSO2 advisory.

WSO2 published the Critical advisory on May 3, 2026 after public fixes merged around April 9–12, 2026. Subscription holders apply listed update levels; community builds apply public GitHub fixes or migrate to an unaffected version. No separate configuration workaround is listed in WSO2-2026-5328.

Technical Information

CVE-2026-5430 is Improper Verification of Cryptographic Signature (CWE-347) in WSO2 JWT authentication. Per WSO2-2026-5328 and NVD: the JWT auth mechanism can accept tokens signed with algorithms other than those explicitly configured or supported. An attacker-crafted JWT using an unsupported algorithm can be incorrectly validated, yielding unauthorized access without legitimate signing keys. Impact includes admin-level account takeover; multi-tenant deployments carry Scope=Changed (CVSS 10.0).

Public fix PR wso2/carbon-apimgt #13752 (merged 2026-04-12) hardens JWT verification for unsupported RSA algorithm variants and related OAuth interceptor exception handling—confirming the remediation path is JWT validation hardening. A second community PR (product-apim #14167) is listed in the vendor advisory. Do not treat fix PRs as exploit recipes.

WatchTowr (via SecurityWeek): forged tokens can yield access to API backend endpoints and credentials, plus consumer keys/secrets for registered applications; gateway position enables interception of traffic toward internal systems. That framing is researcher narrative only—primary sources in this pack do not publish MITRE ATT&CK technique IDs. This advisory does not invent ATT&CK mappings or actor attribution.

Credits: Hacktron Team (responsible disclosure per WSO2-2026-5328).

Affected Product Versions

Vendor: WSO2.

Product Affected versions (advisory) Fixed update level (subscription)
WSO2 API Control Plane 4.6.0, 4.5.0 4.6.0 → UL 22; 4.5.0 → UL 58
WSO2 API Manager 4.6.0, 4.5.0, 4.4.0, 4.3.0, 4.2.0, 4.1.0 4.6.0 → 21; 4.5.0 → 57; 4.4.0 → 72; 4.3.0 → 108; 4.2.0 → 197; 4.1.0 → 257
WSO2 Traffic Manager 4.6.0, 4.5.0 4.6.0 → 21; 4.5.0 → 56
WSO2 Universal Gateway 4.6.0, 4.5.0 4.6.0 → 21; 4.5.0 → 57

NVD CPE aligns with API Manager 4.1.0 through 4.6.0 below fixed ULs, and Control Plane / Traffic Manager / Universal Gateway 4.5.0 and 4.6.0 below listed ULs. NVD also lists Carbon API Manager REST API Utility Maven package lines (org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util) in several 9.20.x–9.32.x ranges as affected.

Community / open source: apply https://github.com/wso2/carbon-apimgt/pull/13752 and https://github.com/wso2/product-apim/pull/14167, or migrate to the latest unaffected product version.

Exposure priority: internet-reachable management and API surfaces (admin / publisher / devportal) are highest priority for inventory and patching.

Workaround and Mitigation

  1. Subscription holders: apply the fixed update levels (or higher) via WSO2 Updates per WSO2-2026-5328.
  2. Community deployments: apply the public GitHub fixes or migrate to an unaffected version.
  3. WSO2-2026-5328 lists no separate configuration workaround (no documented temporary “disable JWT path” knob).
  4. Until patched (secondary defensive guidance, Beazley Security): restrict internet-facing management/gateway access to trusted admin networks.
  5. If exposure is suspected: rotate admin credentials, consumer keys/secrets, and backend credentials; review admin accounts for unauthorized changes; complete forensic review consistent with CISA BOD 26-04 triage expectations.
  6. CISA KEV requiredAction: apply vendor mitigations; comply with BOD 26-04 and Forensics Triage Requirements; for cloud services follow BOD 26-04 cloud guidance or discontinue use if mitigations unavailable; evaluate internet exposure.

Do not close residual risk on “patched” alone when JWT/admin APIs were externally reachable during the exploitation window—credential rotation and auth-log review remain part of close criteria.

Indicators of Compromise

No classic IoCs (IPs, file hashes, domains, or sample token fingerprints) are published in WSO2-2026-5328, CISA KEV, or NVD. Honest empty for those categories.

Behavioral / hunting notes from secondary sources only (not vendor IoCs):

  • SecurityWeek / WatchTowr: forged JWTs with admin privileges observed on honeypots from ~2026-09-13.
  • Beazley (secondary): review auth logs for JWT acceptance with unexpected or unsupported algorithms; successful auths without a matching IdP login; HTTP 200 to /api/am/admin/, /api/am/publisher/, /api/am/devportal/ in repository/logs/http_access_*.log; new or privileged admin accounts; unexpected consumer-key or backend-credential use.

Do not invent ATT&CK technique IDs or additional IoCs beyond what primary and clearly labeled secondary sources publish.

References

Third-Party Risk Bridge: WSO2 as SaaS / API Control-Plane Dependency

WSO2 API Manager, Universal Gateway, API Control Plane, and Traffic Manager commonly sit as SaaS or on-prem API control-plane components in customer and supplier stacks—integration middleware where JWT authn bypass with CVSS 10.0 (multi-tenant) / 9.8 (single-tenant) and forged-admin JWT exploitation from ~September 13, 2026 is a TPRM control-plane ask, not a one-line ticket. Ask every MSP, integrator, or SaaS provider: Do you run these WSO2 products for us? What version and update level (vs the fixed UL table)? Were JWT admin/publisher/devportal APIs internet-exposed before patch? If yes, what forensic review and rotation of admin credentials, consumer keys/secrets, and backend credentials was completed under BOD 26-04 triage expectations?

Book a demo to see how Rescana tracks API-gateway and control-plane vendors for KEV exposure, update-level attestation, and post-exploitation evidence.

Forward this advisory to your TPRM owner if a supplier, MSP, or OEM embeds WSO2 API Manager or Gateway in services you depend on—they own the UL attestation, exposure window, and credential-rotation asks above.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.