WSO2 API Manager - Authentication Bypass via JWT Signature Flaw
WSO2 API Manager is an open-source platform designed for creating, publishing, managing, and monitoring APIs throughout their entire lifecycle, enabling organizations to secure and scale their digital services efficiently. CVE-2026-5430 Critical authentication bypass vulnerability exists in WSO2 API Manager due to an improper signature verification flaw during JSON Web Token (JWT) validation. The system fails to correctly validate the signing algorithm of incoming tokens, allowing it to accept tokens that use unexpected or unsupported cryptographic algorithms. A remote, unauthenticated attacker can exploit this weakness by crafting malicious, self-signed JWTs, thereby bypassing authentication mechanisms and gaining unauthorized access to protected API resources or management consoles with administrative privileges.




