Particle.news

Critical WSO2 API Manager JWT Flaw Exploited With Forged Admin Tokens

Threat intelligence says the bug causes the product to accept tokens signed with unsupported algorithms, allowing attackers to gain administrative access unless systems are patched.

Overview

  • WSO2 disclosed the authentication-bypass bug in April and May 2026 and it was assigned CVE-2026-5430 with a near‑perfect severity score.
  • WatchTowr captured forged JWTs carrying administrator privileges in its honeypots on Sunday, September 13, and reported that replaying the payload against the real product succeeded.
  • The flaw affects API Manager 4.1.0 through 4.6.0 and related components including API Control Plane, Traffic Manager and Universal Gateway.
  • Successful exploitation can let attackers read or intercept API traffic, extract credentials and keys, and use the gateway to move laterally inside networks.
  • Patches and vendor update levels are available now and operators are urged to apply them, review access logs, and rotate any credentials that may have been exposed.