CVE Tools

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

The Hacker NewsBy The Hacker News

Reported exploitedAPI ManagerAPI Control Plane

Our summary

Active exploitation attempts are targeting CVE-2026-5430, a JWT signature-validation bypass in WSO2 API Control Plane 4.6.0 and 4.5.0; WSO2 API Manager 4.6.0, 4.5.0, 4.4.0, 4.3.0, 4.2.0, and 4.1.0; WSO2 Traffic Manager 4.6.0 and 4.5.0; and WSO2 Universal Gateway 4.6.0 and 4.5.0. Attackers can submit forged tokens with administrator privileges to bypass authentication, potentially exposing API backends, credentials, consumer keys, secrets, and internal services; users should apply WSO2's available fixes immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store