All incidents

WSO2 API Manager JWT bypass flaw (CVE-2026-5430) patched

vulnerabilityopenJun 30, 2026 — Aug 7, 2026
WSO2 API Manager JWT bypass flaw (CVE-2026-5430) enables account takeover

WSO2 has disclosed a critical authentication bypass in its API Manager that allows attackers to hijack user accounts without any interaction, tracking as CVE-2026-5430 with a maximum CVSS score of 10.

The flaw resides in the JWT validation process where the signature check can be skipped, enabling an attacker to forge a valid token and gain full access to any account, according to details in the vendor’s advisory published on its security site. Affected products include WSO2 API Manager, Identity Server and Universal Gateway, with versions prior to the latest patches being vulnerable.

Additional weaknesses were revealed in the same advisory, such as CVE-2026-1728 which scores 9.8 and could lead to privilege escalation, CVE-2025-15039 at 9.4 affecting adaptive authentication mechanisms, and CVE-2026-3418 rated 9.1 relating to arbitrary file uploads. No public exploits or active attacks have been observed yet, but the severity of the JWT bypass makes it a prime target for financially motivated groups.

Versions of WSO2 API Manager from 4.6.0 back to earlier releases are impacted, and the vendor has issued updates that address all four vulnerabilities. Security researchers at SecurityOnline note that the flaw places banking and government APIs at particular risk due to their reliance on token‑based auth.

Administrators should immediately apply the latest patches released by WSO2 and verify that JWT validation is enforced across all services, ensuring that no unsigned or tampered tokens are accepted. Reviewing authentication logs for unexpected token issuance or validation failures can help detect attempted abuse.

Beyond patching, organisations are advised to maintain an up‑to‑date inventory of WSO2 components, test updates in a staging environment before rollout, and subscribe to the vendor’s security mailing list for future advisories. Taking these steps will reduce the likelihood of account takeover and protect critical APIs from compromise.

Intelligence briefing updated Aug 7, 2026

CVE-2026-5430 10.0 CVE-2026-1728 9.8 CVE-2025-15039 9.4 CVE-2026-3418 9.1
Root sourcesecurity.docs.wso2.com
Timeline Coverage

Swipe to explore timeline