AI Weekly Malaysia

Back to items Summaries

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

ID
24982
Status
summarized
Published
16 Sep 2026, 1:18 PM
Fetched
16 Sep 2026, 4:16 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
16 Sep 2026, 4:20 PM
Tags
Audience
developersdatabase_learnerssaas_founders

What happened

A critical JWT bypass vulnerability (CVE-2026-5430, CVSS 9.8) in WSO2 API Manager is under active exploitation, with watchTowr honeypots capturing forged admin-privilege tokens on September 13, 2026. The flaw allows authentication bypass when a token is signed with an unsupported algorithm that the service accepts anyway, enabling full account takeover. It affects WSO2 API Manager 4.1.0–4.6.0, API Control Plane 4.5.0–4.6.0, Traffic Manager, and Universal Gateway, with fixes available via specific update levels.

Why it matters

If you operate WSO2 API Manager or related WSO2 gateway products on versions 4.1.0 through 4.6.0, patch immediately to the listed update levels—attackers are actively sending forged admin JWTs. This is a trivial-to-exploit auth bypass, not a theoretical risk, and WSO2 is common in enterprise, telco, and government API stacks across Southeast Asia.

Discussion angle

Walk through the root cause—accepting JWTs signed with unsupported algorithms—and why this class of crypto-verification bug keeps recurring across identity systems, plus a quick check on whether any WSO2 deployments in the audience's org are exposed.

Top