Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Summary
| CVE | CVE-2026-5430 |
|---|---|
| State | PUBLISHED |
| Assigner | WSO2 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:33 UTC |
| Updated | 2026-08-10 12:35:29 UTC |
| Description | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary. |
Risk And Classification
Primary CVSS: v3.1 10 CRITICAL from ed10eef1-636d-4fbe-9993-6890dfa878f8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.002230000 probability, percentile 0.128970000 (date 2026-08-09)
Problem Types: CWE-347 | CWE-347 CWE-347: Improper Validation of Certificate With Host Mismatch
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ed10eef1-636d-4fbe-9993-6890dfa878f8 | Secondary | 10 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 10 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wso2 | Api Control Plane | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.5.0 4.5.0.57 custom | Not specified |
| CNA | WSO2 | WSO2 Universal Gateway | affected 4.6.0 4.6.0.21 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.5.0 4.5.0.56 custom | Not specified |
| CNA | WSO2 | WSO2 Traffic Manager | affected 4.6.0 4.6.0.21 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.5.0 4.5.0.58 custom | Not specified |
| CNA | WSO2 | WSO2 API Control Plane | affected 4.6.0 4.6.0.22 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | unknown 4.1.0 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.1.0 4.1.0.257 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.2.0 4.2.0.197 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.3.0 4.3.0.108 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.4.0 4.4.0.72 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.5.0 4.5.0.57 custom | Not specified |
| CNA | WSO2 | WSO2 API Manager | affected 4.6.0 4.6.0.21 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | affected 9.20.74 9.20.74.401 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | affected 9.28.116 9.28.116.417 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | affected 9.29.120 9.29.120.236 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | affected 9.30.67 9.30.67.167 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | affected 9.31.86 9.31.86.158 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | affected 9.32.147 9.32.147.59 custom | Not specified |
| CNA | WSO2 | WSO2 Carbon API Manager Rest API Utility | unaffected 9.33.106 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO... | ed10eef1-636d-4fbe-9993-6890dfa878f8 | security.docs.wso2.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: hacktron.ai (en)
Additional Advisory Data
Solutions
CNA: Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/#solution https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/#solution
There are currently no legacy QID mappings associated with this CVE.