← Back to CVE List
Vulnerability Intelligence Report
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover

CVE-2026-5430

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-347 ↗CWE-347: Improper Validation of Certificate With Host Mismatch

Affected Products & Versions

Vendor Product Affected Versions
WSO2 WSO2 Universal Gateway 4.5.0 < 4.5.0.57 (affected), 4.6.0 < 4.6.0.21 (affected)
WSO2 WSO2 Traffic Manager 4.5.0 < 4.5.0.56 (affected), 4.6.0 < 4.6.0.21 (affected)
WSO2 WSO2 API Control Plane 4.5.0 < 4.5.0.58 (affected), 4.6.0 < 4.6.0.22 (affected)
WSO2 WSO2 API Manager 0 < 4.1.0 (unknown), 4.1.0 < 4.1.0.257 (affected), 4.2.0 < 4.2.0.197 (affected), 4.3.0 < 4.3.0.108 (affected), 4.4.0 < 4.4.0.72 (affected), 4.5.0 < 4.5.0.57 (affected), 4.6.0 < 4.6.0.21 (affected)
WSO2 WSO2 Carbon API Manager Rest API Utility 9.20.74 < 9.20.74.401 (affected), 9.28.116 < 9.28.116.417 (affected), 9.29.120 < 9.29.120.236 (affected), 9.30.67 < 9.30.67.167 (affected), 9.31.86 < 9.31.86.158 (affected), 9.32.147 < 9.32.147.59 (affected), 9.33.106 <= * (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityWSO2 LLC · Vendor · USA
Reserved2026-04-02T16:11:32
Published2026-08-06T07:33:28
Last Updated2026-08-06T12:30:55

LINK COPIED TO CLIPBOARD