Skip to content

Security1 publisher2 min readPublished

Forged admin JWTs are landing on WSO2 API Manager four months after the fix shipped

CVE-2026-5430 lets a token signed with an algorithm WSO2 does not support pass authentication as an administrator. watchTowr says tokens with administrator privileges baked in reached its honeypots on September 13.

The Watch · Security desk

Photograph accompanying Forged admin JWTs are landing on WSO2 API Manager four months after the fix shipped
Photo: cyberdaily.au

What happened

  • CVE-2026-5430 is an improper cryptographic signature verification flaw in WSO2 API Manager, scored 9.8 out of 10.0, that can end in account takeover.
  • It affects API Manager 4.1.0 through 4.6.0, plus versions 4.5.0 and 4.6.0 of WSO2 API Control Plane, Traffic Manager and Universal Gateway.
  • watchTowr says its honeypot network captured JWT tokens with administrator privileges baked in arriving on September 13, 2026, which it calls active in-the-wild exploitation attempts.
  • WSO2 has released the fix to support subscription holders as numbered update levels, reaching update level 257 for API Manager 4.1.0.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost Community users take the fix from pull requests, so the change lands as a source build and redeploy of the gateway; support subscription holders apply an update level. Same CVE, two different work packages.
  • decision Operators of internet-facing gateways that were behind on update levels now have to decide whether to rotate consumer keys and secrets on the assumption a forged token already read them.
  • contradiction The advisory carries a 9.8 score while watchTowr's Ganchev calls it a CVSS 10.0 bug. The gap changes nothing about patch order, but it tells you the public severity record is not settled.

Signature validation that fails open is the whole bug. "The flaw exists in the service due to how JWT authentication accepts tokens signed with algorithms it does not support, then approves them anyway," Yordan Ganchev, principal threat intelligence specialist at watchTowr, said in a statement shared with The Hacker News [7]. WSO2 describes the same behaviour in its advisory: "JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access" [2]. The vendor added that successful exploitation "may lead to unauthorized access, including potential compromise of administrative accounts and full account takeover" [3].

The evidence for exploitation is honeypot traffic. watchTowr's network captured tokens with administrator privileges already inside them [6]. What an attacker did after that is inference: Ganchev said the forged token is suspected to give access to every API backend endpoint and its credentials, along with consumer keys and secrets for every registered application [10]. watchTowr's account does not name a compromised production deployment.

An API gateway sits in the traffic path by design. "The service is also by definition made to intercept API requests on their way to internal systems, which provides a great opportunity to tap and steal sensitive data in transit and interact with internal services through this 'lateral movement-as-a-service' product," Ganchev said [11].

The published fixes cover twelve product and version combinations [1]. On the 4.6.0 branch the fix is update level 21 for API Manager, Traffic Manager and Universal Gateway, and update level 22 for API Control Plane [8][9]. Older API Manager branches carry higher numbers: 197 for 4.2.0, 108 for 4.3.0, 72 for 4.4.0 [8]. API Control Plane, Traffic Manager and Universal Gateway are listed as affected only at 4.5.0 and 4.6.0, so a gateway estate can need two different remediation paths depending on which components are deployed [4].

Roughly four months separate the advisory from the first captured tokens [2]. Hacktron Team is credited with finding and reporting the flaw [5].

What to watch

  • Whether a WSO2 customer reports credential theft matching the impact watchTowr describes as suspected.
  • Whether the September 13 token traffic resolves to a single actor or to broad commodity scanning.
  • Whether WSO2 adds product versions to the affected list beyond the 4.1.0 to 4.6.0 range already published.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories