WSO2 API Manager and Related Products Improper JWT Signature Verification Vulnerability

Release Date: 24th September 2026 (Added 6th October 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-5430 is a critical vulnerability in multiple WSO2 products caused by improper verification of JSON Web Token (JWT) signatures and algorithms (CWE-347), combined with a path traversal and unrestricted file upload weakness. A token using an unsupported algorithm can be accepted as valid, allowing an unauthenticated remote attacker to take over administrator accounts and potentially achieve remote code execution. CVSS score: 10.0 (Critical). WSO2 tracks it as WSO2-2026-5328.

Reference

  1. https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-5430