Forged tokens breach a CVSS 10 flaw in WSO2’s API manager

Attackers are bypassing JWT authentication in WSO2 middleware that banks, telcos, and governments rely on to broker API traffic.

CSBadmin
2 Min Read

A critical WSO2 vulnerability patched in April is now being exploited against enterprise deployments, exposure management firm watchTowr warned this week.

The flaw is CVE-2026-5430, carrying a maximum CVSS score of 10. Per the vendor’s May advisory, JWT authentication can be bypassed when a token is signed with an algorithm the platform does not support. WSO2 warned that exploitation could mean compromise of administrative accounts and full account takeover.

What the honeypots caught

Affected products span WSO2 API Manager 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway — middleware used by roughly 1,000 enterprise customers in banking, government, telecom, and logistics.

watchTowr’s honeypot network logged the first attempt on September 13, with forged tokens arriving that carried baked-in administrator privileges. “The service is by definition made to intercept API requests on their way to internal systems, which provides a great opportunity to tap and steal sensitive data in transit,” said Yordan Ganchev, principal threat intelligence specialist at watchTowr.

A forged token yields access to every backend endpoint plus the credentials, consumer keys, and secrets for every registered application, he added. The firm reproduced the bug from the vendor patch alone, noting that technical details were never public — and that the attacker it observed had initially targeted the wrong product.

Fixes are available through WSO2 pull requests and subscription update levels. Because exploitation is live, administrators should patch urgently and rotate any keys reachable through an API gateway.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.