Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember

Always First. Fast SOC News.

Response · NEW YORK

CISA Puts WSO2 JWT Auth Bypass CVE-2026-5430 on KEV With Three-Day Clock

By Noah Park, Response, New York

CISA graphic titled The Nation's Risk Managers.
Graphic: CISA.

NEW YORK - The Cybersecurity and Infrastructure Security Agency on September 24, 2026, added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation against WSO2 API infrastructure. Federal civilian agencies face a remediation due date of September 27, 2026, under Binding Operational Directive 26-04. CISA also flags forensic triage for this entry. Known ransomware campaign use is listed as Unknown.

WSO2 documents the flaw in security advisory WSO2-2026-5328. The vendor describes an authentication bypass in JWT handling: authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access. Successful exploitation may lead to unauthorized access, including potential compromise of administrative accounts and full account takeover. WSO2 rates the issue Critical with a CVSS 3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), and adjusts the score to 9.8 with Scope Unchanged for single-tenant deployments. The advisory was published May 3, 2026. Affected products include WSO2 API Manager 4.1.0 through 4.6.0, plus API Control Plane, Traffic Manager, and Universal Gateway on listed 4.5.0 and 4.6.0 lines.

For support subscription holders, WSO2 specifies minimum update levels (or higher): API Manager 4.6.0 update 21, 4.5.0 update 57, 4.4.0 update 72, 4.3.0 update 108, 4.2.0 update 197, and 4.1.0 update 257; API Control Plane 4.6.0 update 22 and 4.5.0 update 58; Traffic Manager 4.6.0 update 21 and 4.5.0 update 56; Universal Gateway 4.6.0 update 21 and 4.5.0 update 57. Community users are pointed to public fixes in the carbon-apimgt and product-apim repositories. If applying a fix is not feasible, WSO2 advises migrating to the latest unaffected version. Credits go to Hacktron Team for reporting the issue.

CISA's KEV short description text references path traversal and unrestricted file upload leading to remote code execution. That catalog wording does not match WSO2's technical advisory for the same CVE ID, which centers on JWT algorithm validation and authentication bypass, consistent with CWE-347 (Improper Verification of Cryptographic Signature) on the KEV record. Operators should follow the vendor patch matrix and treat the KEV listing as the operational urgency signal, not as a substitute for the vendor root-cause description.

For security operations and incident response teams, treat internet-reachable or poorly isolated WSO2 API Manager and related gateway components as an identity and control-plane case. Priority work is inventory of affected product versions, confirmation of update level or migration status, restriction of management and token-validation interfaces to trusted networks, review of authentication and administrative audit logs for anomalous JWT acceptance around the exploitation window, and credential rotation for administrative accounts if compromise cannot be ruled out. Preserve evidence before rebuilding nodes that may have been used with forged tokens.

Noah Park is a Response correspondent covering incident response and blue-team containment for SOCtember, based in New York.

Back to Response