## Overview
CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities (KEV) list on September 24, 2026. This vulnerability affects multiple WSO2 products, including the API Control Plane, API Manager, Traffic Manager, and Universal Gateway. The addition to the KEV list signals a federal deadline for remediation due to evidence of active exploitation.
## Technical Details
CVE-2026-5430 is a path traversal vulnerability within WSO2's JWT authentication mechanism. It allows attackers to craft JSON Web Tokens (JWTs) with unsupported signing algorithms. When these tokens are validated, the system incorrectly accepts them, leading to unauthorized access. The vulnerability has a CVSS score of 10.0, indicating critical severity. In single-tenant deployments, the score adjusts to 9.8, reflecting a contained impact within a single security boundary.
## Impact
Successful exploitation can lead to unauthorized access to systems. Attackers may compromise administrative accounts and execute arbitrary code. This could result in full account takeover and significant data breaches. The potential for unrestricted file uploads exacerbates the risk, allowing attackers to deploy malicious payloads on affected systems.
## Mitigation
Defenders should immediately apply patches released by WSO2 to mitigate this vulnerability. Organizations must review their JWT configurations to ensure only supported algorithms are enabled. Regular security audits and monitoring for unusual authentication attempts can help detect and prevent exploitation. Implementing strict access controls and user permissions is also advisable to limit the impact of any potential breaches.
CSURFACE Threat Sensor