news.mlab.sh
Back to the feed
vulnerability

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

CriticalCVSS 10.0
Summary

A critical security flaw in WSO2 API Manager and related products is currently being actively exploited in the wild. Hacktron Team discovered the vulnerability (CVE-2026-5430, CVSS 9.8/10.0) related to JWT signature verification, allowing attackers to bypass authentication and gain administrative access. WSO2 has released patches, and users are strongly urged to apply them immediately to mitigate the risk of account takeover and data theft.

A critical security flaw in WSO2 API Manager and related products is currently being actively exploited in the wild. Hacktron Team discovered the vulnerability (CVE-2026-5430, CVSS 9.8/10.0) related to JWT signature verification, allowing attackers to bypass authentication and gain administrative access. WSO2 has released patches, and users are strongly urged to apply them immediately to mitigate the risk of account takeover and data theft. The vulnerability stems from the service's acceptance of JWT tokens signed with unsupported algorithms, effectively bypassing security measures. According to watchTowr, active exploitation attempts have been detected since September 13, 2026, with honeypot networks capturing JWT tokens containing baked-in administrator privileges. These tokens are then used to access every API backend endpoint and its credentials, consumer keys, and secrets for every registered application. The service’s ability to intercept API requests on their way to internal systems further amplifies the risk, providing an opportunity to steal sensitive data in transit and interact with internal services. Affected products include: WSO2 API Control Plane (4.6.0, 4.5.0), WSO2 API Manager (4.6.0, 4.5.0, 4.4.0, 4.3.0, 4.2.0, 4.1.0), WSO2 Traffic Manager (4.6.0, 4.5.0), and WSO2 Universal Gateway (4.6.0, 4.5.0). Users are advised to apply the available fixes promptly to ensure optimal protection.

Read the full article at The Hacker News