Overview
- WSO2 disclosed the authentication-bypass bug in April and May 2026 and it was assigned CVE-2026-5430 with a near‑perfect severity score.
- WatchTowr captured forged JWTs carrying administrator privileges in its honeypots on Sunday, September 13, and reported that replaying the payload against the real product succeeded.
- The flaw affects API Manager 4.1.0 through 4.6.0 and related components including API Control Plane, Traffic Manager and Universal Gateway.
- Successful exploitation can let attackers read or intercept API traffic, extract credentials and keys, and use the gateway to move laterally inside networks.
- Patches and vendor update levels are available now and operators are urged to apply them, review access logs, and rotate any credentials that may have been exposed.