www.securityweek.com 16 Sept 2026, 08:39 UTC

Attackers Exploit Critical WSO2 Flaw to Forge JWTs and Steal Secrets

Attackers Exploit Critical WSO2 Flaw to Forge JWTs and Steal Secrets
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

SECURITY researchers have warned that attackers are exploiting CVE-2026-5430, a critical WSO2 vulnerability patched earlier this year. The flaw has a maximum CVSS score of 10 and affects WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway. According to WSO2, JWT authentication can be bypassed when a token is signed with an unsupported algorithm, potentially granting unauthorised access, including administrative account compromise and full account takeover. WSO2’s platform is used by nearly 1,000 enterprise customers worldwide, with additional deployments through open-source users, OEMs and partners.

WatchTowr said its honeypot network recorded the first exploitation attempt on 13 September. The attacker used a forged JWT, which researchers said provided access to API backend endpoints, credentials, consumer keys and secrets for registered applications. Because the affected service can intercept API requests to internal systems, successful exploitation could also enable data theft and interaction with internal services.

WatchTowr said it observed one attacker targeting the wrong product, but confirmed that replaying the payload against the genuine WSO2 product worked. The company said it reproduced the vulnerability from WSO2’s patch, although technical details were not yet publicly available and the CVE record was only published in early August. Organisations using affected products should apply WSO2’s available fixes and investigate exposed systems for unauthorised access.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline