JWT Authentication Vulnerability in WSO2 Products
CVE-2026-5430

10CRITICAL

What is CVE-2026-5430?

The vulnerability in WSO2 products relates to the JWT authentication mechanism, which improperly validates tokens signed with algorithms not explicitly configured or supported. This flaw enables an attacker to create a JSON Web Token (JWT) using an unsupported signing algorithm. If an attacker successfully exploits this vulnerability, they can gain unauthorized access to the system, potentially compromising administrative accounts and leading to full account takeovers. Organizations using affected versions of WSO2 Identity Server should prioritize implementing protective measures to mitigate the risks associated with this security flaw.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.58

WSO2 API Control Plane 4.6.0 < 4.6.0.22

WSO2 API Manager 4.1.0 < 4.1.0.257

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hacktron.ai
.