• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

CVE-2026-5430: Full Account Takeover in WSO2 API Management Products Now Actively Exploited

Blog

CVE-2026-5430 (CVSS 10), published August 6th, 2026, is a critical authentication bypass in WSO2 JSON Web Token (JWT) authentication affecting multiple WSO2 API management products. The flaw allows a token signed with an unsupported algorithm to bypass JWT authentication. Exploitation allows unauthorized access, compromise of administrative accounts, and full account takeover. Although the CVE was issued in August, the vendor had already published an early-warning security advisory WSO2-2026-5328 in May.

watchTowr’s honeypot observed malicious attacks beginning on September 13th, 2026. CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities (KEV) catalog on September 24th. Global risk is high because WSO2 reports more than 950 paying customers across 90+ countries, including numerous large corporate customers and critical infrastructure entities. Furthermore, a detailed technical analysis with proof-of-concept (PoC) exploit is publicly available and the vendor’s own public repository includes commit details that can help reverse engineer the flaw.

Banner graphic reading CVE-2026-5430: Account Takeover in WSO2, shown over a shattered security shield illustration

Detected Before the CVE Was Even Published

Before a CVE was published, Greenbone’s OPENVAS ENTERPRISE FEED included separate remote banner checks for CVE-2026-5430 in WSO2 API Manager[1][2][3], WSO2 Traffic Manager, and Universal Gateway. This scenario highlights the risks defenders face when a CVE ID is not published promptly and the need to identify and patch vulnerabilities before they are targeted in malicious attacks. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

A Global Risk Assessment of CVE-2026-5430 in WSO2 API Management Products

CVSS 10 · CriticalEPSS 0.6% (46th)Actively exploitedIn CISA KEVPublic PoC

WSO2 rates the issue as Critical; CVE-2026-5430 is a network-reachable vulnerability that can be exploited without authentication, and with a low-complexity attack vector. Malicious attacks were observed in mid-September, and CISA has added CVE-2026-5430 to its KEV list. Furthermore, a detailed technical analysis with PoC exploit is publicly available, and the vendor’s own public repository includes commit details that can help reverse engineer the flaw. WSO2 states that successful exploitation allows unauthorized access, including compromise of administrative accounts and full account takeover in WSO2 API Control Plane, WSO2 API Manager, WSO2 Traffic Manager, and WSO2 Universal Gateway.

WSO2 reports more than 950 paying customers across 90+ countries, including numerous large-corporate customers and critical infrastructure entities. The platform is used across cloud, on-premise, and hybrid deployments. The WSO2 API Manager, Admin Portal, and Developer Portal are used to manage API keys and credentials while the Key Manager handles authentication, authorization, and tokens. In that context, a JWT authentication bypass affects systems that are directly involved in identity and access decisions.

WSO2 API management can span multiple gateway runtimes through a unified control plane and via the WSO2 Traffic Manager. The Traffic Manager and Universal Gateway enable rate limiting across gateway nodes. Given the architecture, an authentication bypass could have a broad operational impact across distributed deployments. CVE-2026-5430 was assigned a CVSS score of 10 for multi-tenant deployments and CVSS 9.8 for single-tenant deployments, where the impact is limited to a single security authority boundary.

Technical Details for CVE-2026-5430 in WSO2 API Management Products

CVE-2026-5430 is caused by flawed exception handling [CWE-703] during JWT authentication. When a token is signed using an unsupported algorithm, JWT validation failure results in fail open rather than fail closed behavior. The result is an improper verification of a token’s cryptographic signature [CWE-347].

Under normal conditions, an authenticator returning false causes an AuthenticationException and prevents the request from reaching the protected API. However, in the vulnerable code, an APIManagementException is logged, but no failed authentication state is set, allowing full access to the REST API.

Affected Products and Mitigation for CVE-2026-5430

Detected Before the CVE Was Even Published

Before a CVE was published, Greenbone’s OPENVAS ENTERPRISE FEED included separate remote banner checks for CVE-2026-5430 in WSO2 API Manager[1], Traffic Manager[2], and Universal Gateway[3]. This scenario highlights the risks defenders face when a CVE ID is not published promptly and the need to identify and patch vulnerabilities before they are targeted in malicious attacks.

CVE-2026-5430 affects various versions of WSO2 API Control Plane, WSO2 API Manager, Traffic Manager, and Universal Gateway. The vendor has published product-specific updates that address CVE-2026-5430. Organizations running affected releases should move each deployment to the corresponding update level for its product branch.

The affected products, affected versions, and fixed versions are shown below:

Product Affected versions Fixed versions

WSO2 API Control Plane

4.6.0

4.5.0

4.6.0 update level 22

4.5.0 update level 58

WSO2 API Manager

4.6.0

4.5.0

4.4.0

4.3.0

4.2.0

4.1.0

4.6.0 update level 21

4.5.0 update level 57

4.4.0 update level 72

4.3.0 update level 108

4.2.0 update level 197

4.1.0 update level 257

WSO2 Traffic Manager

4.6.0

4.5.0

4.6.0 update level 21

4.5.0 update level 56

WSO2 Universal Gateway

4.6.0

4.5.0

4.6.0 update level 21

4.5.0 update level 57

Summary

CVE-2026-5430 is a critical WSO2 JWT authentication bypass that can allow unauthorized access, administrative account compromise, and full account takeover. The flaw affects WSO2 API Control Plane, WSO2 API Manager, Traffic Manager, and Universal Gateway. Observation of malicious attacks further increases the risk associated with CVE-2026-5430. Organizations with WSO2 products in their IT environment should treat the published update levels as an immediate remediation requirement.

Detected Before the CVE Was Even Published

Before a CVE was published, Greenbone’s OPENVAS ENTERPRISE FEED included separate remote banner checks for CVE-2026-5430 in WSO2 API Manager[1][2][3], WSO2 Traffic Manager, and Universal Gateway. This scenario highlights the risks defenders face when a CVE ID is not published promptly and the need to identify and patch vulnerabilities before they are targeted in malicious attacks. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

 

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

30. September 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-09-30 12:07:062026-09-30 12:07:06CVE-2026-5430: Full Account Takeover in WSO2 API Management Products Now Actively Exploited

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: New Distributor Partnership: CoreWin Brings OPENVAS to Ukraine and the Region Link to: New Distributor Partnership: CoreWin Brings OPENVAS to Ukraine and the Region New Distributor Partnership: CoreWin Brings OPENVAS to Ukraine and the Regi...
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn