WSO2 API Manager and Related Products Improper JWT Signature Verification Vulnerability
Release Date: 24th September 2026 (Added 6th October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-5430 is a critical vulnerability in multiple WSO2 products caused by improper verification of JSON Web Token (JWT) signatures and algorithms (CWE-347), combined with a path traversal and unrestricted file upload weakness. A token using an unsupported algorithm can be accepted as valid, allowing an unauthenticated remote attacker to take over administrator accounts and potentially achieve remote code execution. CVSS score: 10.0 (Critical). WSO2 tracks it as WSO2-2026-5328.
What are the systems affected?
The following WSO2 products are affected prior to the fixed builds:
WSO2 API Manager: before 4.1.0.257, 4.2.0.197, 4.3.0.108, 4.4.0.72, 4.5.0.57 and 4.6.0.21 (per release train) – (Affected)
WSO2 API Control Plane: before 4.5.0.58 and 4.6.0.22 – (Affected)
WSO2 Traffic Manager: before 4.5.0.56 and 4.6.0.21 – (Affected)
WSO2 Universal Gateway: before 4.5.0.57 and 4.6.0.21 – (Affected)
Not affected / patched version:
The fixed builds listed above or later for each product and release train, as published in WSO2 security advisory WSO2-2026-5328 – (Not affected)
What does this mean?
Successful exploitation may allow attackers to:
- Forge or manipulate JWTs to bypass authentication without valid credentials
- Take over administrator accounts on the API management platform
- Upload malicious files and achieve remote code execution, compromising APIs, backend services and the credentials they handle
Mitigation process?
CERTVU recommends the following:
-
Patch Immediately
Update all affected WSO2 products to the fixed builds in advisory WSO2-2026-5328 as an emergency change. -
Inventory and Restrict Exposure
-
Hunt for Compromise
-
Rotate Credentials and Secrets
After patching, rotate administrator passwords, API keys, keystore secrets and any credentials stored on the platform.
Reference
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-5430
- Download advisory (English): WSO2 API Manager and Related Products Improper JWT Signature Verification Vulnerability