Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
- ID
- 24982
- Status
- summarized
- Published
- 16 Sep 2026, 1:18 PM
- Fetched
- 16 Sep 2026, 4:16 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 16 Sep 2026, 4:20 PM
- Tags
- Audience
- developersdatabase_learnerssaas_founders
What happened
A critical JWT bypass vulnerability (CVE-2026-5430, CVSS 9.8) in WSO2 API Manager is under active exploitation, with watchTowr honeypots capturing forged admin-privilege tokens on September 13, 2026. The flaw allows authentication bypass when a token is signed with an unsupported algorithm that the service accepts anyway, enabling full account takeover. It affects WSO2 API Manager 4.1.0–4.6.0, API Control Plane 4.5.0–4.6.0, Traffic Manager, and Universal Gateway, with fixes available via specific update levels.
Why it matters
If you operate WSO2 API Manager or related WSO2 gateway products on versions 4.1.0 through 4.6.0, patch immediately to the listed update levels—attackers are actively sending forged admin JWTs. This is a trivial-to-exploit auth bypass, not a theoretical risk, and WSO2 is common in enterprise, telco, and government API stacks across Southeast Asia.
Discussion angle
Walk through the root cause—accepting JWTs signed with unsupported algorithms—and why this class of crypto-verification bug keeps recurring across identity systems, plus a quick check on whether any WSO2 deployments in the audience's org are exposed.