WSO2 API Manager
JWT algorithm confusion lets unauthenticated attackers forge admin tokens in WSO2 API Manager (CVE-2026-5430)
watchTowr reports active exploitation attempts using forged admin tokens, so an unpatched, internet-facing WSO2 gateway can be taken over without credentials by anyone replaying the technique.
The JWT authentication mechanism in WSO2 API Manager, Universal Gateway, Traffic Manager and API Control Plane accepts tokens signed with algorithms other than those configured, so an unauthenticated attacker can craft a token that passes validation. The result is unauthorized access up to administrative account takeover, with cross-tenant impact in multi-tenant deployments.
Affected: WSO2 API Manager 4.1.0 < 4.1.0.257; WSO2 API Manager 4.2.0 < 4.2.0.197; WSO2 API Manager 4.3.0 < 4.3.0.108; WSO2 API Manager 4.4.0 < 4.4.0.72; WSO2 Universal Gateway 4.5.0 < 4.5.0.57; WSO2 Universal Gateway 4.6.0 < 4.6.0.21; WSO2 Traffic Manager 4.5.0 < 4.5.0.56; WSO2 Traffic Manager 4.6.0 < 4.6.0.21; WSO2 API Control Plane 4.5.0 < 4.5.0.58; WSO2 API Control Plane 4.6.0 < 4.6.0.22
Confirm the product and update level of every WSO2 API Manager, Universal Gateway, Traffic Manager and API Control Plane node against the fixed update levels above; anything below is vulnerable. Review gateway and key-manager authentication logs for accepted JWTs whose header algorithm differs from the configured signing algorithm, and audit recent administrative logins, new admin users, and API/application changes that no operator can account for.
Update to API Manager 4.1.0.257, 4.2.0.197, 4.3.0.108 or 4.4.0.72; Universal Gateway 4.5.0.57 or 4.6.0.21; Traffic Manager 4.5.0.56 or 4.6.0.21; API Control Plane 4.5.0.58 or 4.6.0.22, per WSO2 advisory WSO2-2026-5328. Until updated, restrict network access to the management and admin interfaces to trusted sources.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
