CVE-2026-5430

Summary

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.

Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

Affected Software

VendorProductVersion RangeStatus
WSO2WSO2 Universal Gateway4.5.0 < 4.5.0.57affected
WSO2WSO2 Universal Gateway4.6.0 < 4.6.0.21affected
WSO2WSO2 Traffic Manager4.5.0 < 4.5.0.56affected
WSO2WSO2 Traffic Manager4.6.0 < 4.6.0.21affected
WSO2WSO2 API Control Plane4.5.0 < 4.5.0.58affected
WSO2WSO2 API Control Plane4.6.0 < 4.6.0.22affected
WSO2WSO2 API Manager0 < 4.1.0unknown
WSO2WSO2 API Manager4.1.0 < 4.1.0.257affected
WSO2WSO2 API Manager4.2.0 < 4.2.0.197affected
WSO2WSO2 API Manager4.3.0 < 4.3.0.108affected
WSO2WSO2 API Manager4.4.0 < 4.4.0.72affected
WSO2WSO2 API Manager4.5.0 < 4.5.0.57affected
WSO2WSO2 API Manager4.6.0 < 4.6.0.21affected
WSO2WSO2 Carbon API Manager Rest API Utility9.20.74 < 9.20.74.401affected
WSO2WSO2 Carbon API Manager Rest API Utility9.28.116 < 9.28.116.417affected
WSO2WSO2 Carbon API Manager Rest API Utility9.29.120 < 9.29.120.236affected
WSO2WSO2 Carbon API Manager Rest API Utility9.30.67 < 9.30.67.167affected
WSO2WSO2 Carbon API Manager Rest API Utility9.31.86 < 9.31.86.158affected
WSO2WSO2 Carbon API Manager Rest API Utility9.32.147 < 9.32.147.59affected
WSO2WSO2 Carbon API Manager Rest API Utility9.33.106 <= *unaffected

Weaknesses

  • CWE-347: CWE-347: Improper Validation of Certificate With Host Mismatch

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References