Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-5430: Unsupported JWT Algorithm Allows Unauthorized Access in [Software Name]
CVE-2026-5430 · published 29 days ago
Summary
The JWT authentication in [Software Name] can accept tokens signed with unknown algorithms, allowing attackers to gain unauthorized access to the system. This could lead to the compromise of administrative accounts and full account takeover. To prevent this, ensure that the JWT authentication mechanism only accepts tokens signed with explicitly configured and supported algorithms.
What to do
- Update wso2 wso2 universal gateway to version 4.5.0.57 or later.
- Update wso2 wso2 traffic manager to version 4.5.0.56 or later.
- Update wso2 wso2 api control plane to version 4.5.0.58 or later.
- Update wso2 wso2 api manager to version 4.1.0.257 or later.
- Update wso2 wso2 carbon api manager rest api utility to version 9.20.74.401 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wso2 | wso2 universal gateway | < 4.5.0.57 |
| wso2 | wso2 traffic manager | < 4.5.0.56 |
| wso2 | wso2 api control plane | < 4.5.0.58 |
| wso2 | wso2 api manager | < 4.1.0.257 |
| wso2 | wso2 carbon api manager rest api utility | < 9.20.74.401 |
Original advisory text
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.
Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published6 Aug 2026
Updated24 Aug 2026
First seen6 Aug 2026
Monitor software like this
Free during beta