securityonline.info 8/7/2026, 2:02:49 PM · external

WSO2 Flaws Enable Account Takeover Via JWT Bypass, Patch Urged

WSO2 Flaws Enable Account Takeover Via JWT Bypass, Patch Urged
Developing story vulnerability 2 articles tracked
WSO2 API Manager JWT bypass flaw (CVE-2026-5430) patched
CyberSIXT Evidence Panel

WSO 2 disclosed four critical security vulnerabilities affecting its API Manager, Identity Server, and Universal Gateway products. The most severe flaw, CVE-2026-5430, has a CVSS score of 10, allowing for an account takeover via a JWT authentication bypass. Other vulnerabilities include CVE-2026-1728 (9.8), leading to privilege escalation, CVE-2025-15039 (9.4) concerning adaptive authentication flaws, and CVE-2026-3418 (9.1) related to arbitrary file uploads. No confirmed exploitations have occurred yet, and patches are available. It's advised that administrators update their systems to the latest versions.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline