Skip to content
Vulnerability in open

Vulnerability in open

Cyberdaily.Au September 16, 2026

Hackers are targeting CVE-2026-5430, a critical authentication bypass vulnerability in WSO2 API Manager, a platform used by banks, telcos, and governments worldwide.

Almost five months after it was first addressed by a patch, a vulnerability in a little-known platform used by high-level enterprises in more than 90 countries worldwide has caught the attention of unidentified hackers.

“watchTowr Intel has identified in-the-wild exploitation attempts of CVE-2026-5430, a critical authentication bypass vulnerability in WSO2 API Manager,” Yordan Ganchev, principal threat intelligence specialist at the company, told Cyber Daily.

“Our Attacker Eye global honeypot network captured forged JWT tokens arriving on September 13 with an ample number of administrator privileges already baked in and ready to ruin someone’s day.”

CVE-2026-5430 was initially addressed by WSO2 in April, with an advisory released in May, and a CVE record following in August. However, with a CVSS score of 10, Ganchev considers the initial pull request’s title of “Improve exception handling” to have been slightly undersold given its critical nature.

It is worth noting that “perfect 10” score drops to “just” 9.8 in single-tenant deployments, “reflecting that the impact is contained within a single security authority boundary”, according to its CVE record.

The vulnerability impacts API Manager 4.1.0 through 4.6.0, API Control Plane, Traffic Manager and Universal Gateway.

“The attacker’s forged JWT token showed us what they were looking to achieve,” Ganchev said.

“The forged token yields access to every API backend endpoint and its credentials, consumer keys and secrets for every registered application. The service is also, by definition, made to intercept API requests on their way to internal systems, which provides a great opportunity to tap and steal sensitive data in transit and interact with internal services through this ‘Lateral Movement-as-a-Service’ product.”

As Ganchev points out, WSO2 may not be a household name, but that doesn’t make it a niche target.

“The vendor reports nearly 1,000 customers across banking, government, telecom and logistics in 90+ countries. We observed a single attacker targeting the wrong product, but when we replayed their payload on the real one – it worked,” Ganchev said.

“Our honeypots were fortunate to be mixed up, but the same may not be guaranteed real victim systems.”

David Hollingworth has been writing technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk Lego.

Extracted Entities