WSO 2 disclosed four critical security vulnerabilities affecting its API Manager, Identity Server, and Universal Gateway products. The most severe flaw, CVE-2026-5430, has a CVSS score of 10, allowing for an account takeover via a JWT authentication bypass. Other vulnerabilities include CVE-2026-1728 (9.8), leading to privilege escalation, CVE-2025-15039 (9.4) concerning adaptive authentication flaws, and CVE-2026-3418 (9.1) related to arbitrary file uploads. No confirmed exploitations have occurred yet, and patches are available. It's advised that administrators update their systems to the latest versions.
WSO2 Flaws Enable Account Takeover Via JWT Bypass, Patch Urged
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
WSO2 Flaws Enable Account Takeover Via JWT Bypass, Patch Urged
securityonline.info
-
WSO2 patches critical JWT bypass flaw, putting bank APIs at risk
cybersixt.com