Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: jwt-bypass (1 article)Clear

Attackers forge admin tokens through a WSO2 API Manager JWT bypass flaw

Attackers are exploiting a JWT authentication-bypass flaw in WSO2 products, including its widely used API Manager and Identity Server. Tracked as CVE-2026-5430 and rated 9.8, the flaw is an algorithm-confusion bug: the token validator accepts JWTs signed with algorithms other than the ones it is configured to trust, so an attacker can craft a forged token that passes validation. That lets them mint tokens as an administrator and take over the deployment, gaining control over the APIs and identities the platform manages. Because WSO2 sits at the center of API and identity infrastructure, a takeover can cascade to everything behind the gateway. Active exploitation attempts have been observed against exposed instances.

Check
Apply WSO2's fixes for the JWT authentication-bypass flaw across API Manager, Identity Server, and other affected products, and keep the Carbon management console and admin interfaces off the public internet.
Affected
Organizations running affected WSO2 products such as API Manager or Identity Server (CVE-2026-5430); an attacker can forge a JWT with an unsupported algorithm to bypass authentication, become an administrator, and take over.
Fix
Patch to fixed WSO2 versions, restrict management interfaces to trusted networks, enforce strict JWT algorithm validation, monitor for forged-token and anomalous admin activity, and rotate keys and tokens if compromise is suspected.