OFFSEC · Offensive Security

CISA catalogued the exploited WSO2 flaw as a file upload bug. It is a forged-token bypass, and its fix sat in public for five months

CVE-2026-5430 lets an unauthenticated attacker present a forged administrator token to WSO2's API management products. The KEV entry added on 24 September describes a path traversal and file upload instead, which points responders at evidence this attack does not leave, and the code fix had been readable on GitHub since April.

The finding

On 24 September 2026 CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue, one of them CVE-2026-5430, which it named “WSO2 Multiple Products Path Traversal Vulnerability” [2]. The catalogue entry describes a path traversal that “could allow for unrestricted file upload and lead to remote code execution”, sets a remediation date of 27 September, and marks the entry for forensic triage under Binding Operational Directive 26-04 [3][8]. The same entry's weakness field records CWE-347, improper verification of a cryptographic signature [3][13].

The CWE field is right and the prose is not. WSO2's advisory for CVE-2026-5430 describes a JSON Web Token (JWT) authentication bypass and nothing else [1], and none of the sources reviewed for this article describes a path traversal or file upload component. The catalogue's wording closely matches its entry for CVE-2022-29464, a different WSO2 flaw added in April 2022 and described as unrestricted file upload resulting in remote code execution, under CWE-22 [3]. The most likely explanation is a template carried over from the earlier WSO2 entry, though CISA has not said so.

This is more than a clerical point. A KEV description is what many organisations paste into a ticket, and the forensic triage flag tells responders to establish whether a system was compromised before it was patched [3]. Read literally, the entry sends them looking for uploaded files and web shells. The actual attack presents a forged token to an interface that trusts it, and writes nothing to disk.

“access to every API backend endpoint and its credentials, consumer keys and secrets for every registered application”

Yordan Ganchev, principal threat intelligence specialist, watchTowr, describing what a forged token provides, as reported by SecurityWeek [4]

What the flaw actually is

WSO2 published advisory WSO2-2026-5328 on 3 May 2026. It covers API Manager 4.1.0 to 4.6.0, API Control Plane 4.5.0 and 4.6.0, Traffic Manager 4.5.0 and 4.6.0, and Universal Gateway 4.5.0 and 4.6.0 [1]. WSO2 states that “JWT authentication can be bypassed when a token is signed using an unsupported algorithm”, that exploitation may compromise administrative accounts, and that the CVSS 3.1 score of 10.0 falls to 9.8 in single-tenant deployments because the scope change no longer applies [1]. Some reporting gives 9.8 as the headline figure [5]. The Hacktron Team is credited with the report [1].

The defect sits in a class the standards have warned about for years. RFC 8725, the IETF's best current practice for JWTs, says libraries “MUST enable the caller to specify a supported set of algorithms and MUST NOT use any other algorithms” [12]. The failure here is the reverse: an algorithm outside the supported set does not cause rejection. watchTowr's Yordan Ganchev put it as JWT authentication that accepts tokens signed with algorithms it does not support, “then approves them anyway” [5]. The signature check is the whole of the authentication decision, so a check that can be skipped is no authentication at all.

What an attacker reaches is the API management plane. Field Effect lists the exposure as API configurations, backend endpoints, application credentials, consumer keys and authentication secrets across connected systems [6]. An API gateway is a credential broker by design: it holds the secrets that let registered applications call backends, and the configuration that decides where each call goes.

Five months of a public fix

WSO2's advisory names two pull requests in its open-source repositories as the public fixes [1]. Their history gives the sequence below.

  • 12 April: carbon-apimgt pull request 13752, titled “Improve exception handling”, is merged to master. It changes five lines in the JWT utility class and adjusts the OAuth authentication interceptor for the REST APIs [10].
  • 22 April: product-apim pull request 14167, titled “Improve advanced configuration tests”, adds an integration test [11].
  • 3 May: WSO2 publishes the advisory and update levels for enterprise customers [1].
  • Around 6 August: the CVE record is published with WSO2 as the numbering authority [9]; SecurityWeek dates it to early August [4].
  • 13 September: watchTowr's honeypot network records JWTs arriving with administrator privileges already set [4][5].
  • 16 September: SecurityWeek and The Hacker News report exploitation [4][5].
  • 24 September: CISA adds the flaw to KEV with a 27 September deadline [2][3].

Neutral commit titles for security fixes are common practice and have a reasonable motive: not advertising a flaw before customers can patch. But the code was readable. For three weeks before the advisory, and for almost four months before there was a CVE identifier, the change sat in a public repository, small enough to review in minutes. Anyone watching the repository had the diff. Anyone relying on a scanner that matches CVE identifiers had nothing to match until August.

The usual prioritisation signals stayed quiet throughout. The EPSS score shown for the CVE was 0.32 per cent [9], and none of the sources reviewed for this article publishes a count of internet-exposed instances. The five months between fix and first recorded attack were time defenders had. The honeypot data shows the attackers used it.

A repeat entry in the catalogue

CVE-2022-29464 is the flaw whose description the new entry resembles. CISA added it to KEV on 25 April 2022 with a 16 May deadline and now records it as known to have been used in ransomware campaigns [3]. Rapid7 reported opportunistic exploitation within days of the April 2022 disclosure, with a proof of concept public two days after the CVE and attackers dropping web shells and coin miners on Windows and Linux hosts [14]. Affected products then included API Manager and Identity Server [14].

The two cases leave opposite traces. The 2022 attacks put files on disk, and file integrity monitoring or a web shell sweep found them. The 2026 flaw grants a session. Its evidence is an administrative action with no matching login at the identity provider, a token carrying an unexpected algorithm value, or a bulk read of application credentials [7]. A responder who learnt WSO2 incident response in 2022, and who reads the 2026 entry as written, will run the wrong playbook.

Why a gateway compromise travels

SecurityWeek reports that WSO2 has nearly 1,000 enterprise customers in banking, government, telecommunications and logistics, plus open-source users beyond that [4]. The vendor now markets the same platform as “The Open Platform to Control APIs, AI, and MCP”, with an AI gateway to “govern and manage LLM and MCP at scale” and tooling that turns existing APIs into tools for AI agents [15]. Where a deployment is used that way, administrator access on the gateway decides what agents can call and with whose credentials.

That is why the remediation scope is wider than the binary. Applying the update level closes the bypass. It does not reverse a backend endpoint redirected while the gateway was exposed, and it does not change a consumer secret that was read. Field Effect's guidance accordingly includes auditing API configurations for unauthorised changes and rotating exposed credentials [6].

Regional note

No Malaysian national advisory for CVE-2026-5430 could be identified as at publication; the alerts page of the National Cyber Security Agency (NACSA) lists nothing after 30 June 2026 [16]. This desk also found no public data on WSO2 deployment numbers in Malaysia or Southeast Asia, so no regional exposure figure is offered. The sectors SecurityWeek names, banking and government among them [4], are the sectors most of the region's open API and digital government programmes sit in. Operators there should not wait for a national prompt, and should work from WSO2's advisory rather than the catalogue text.

What defenders should do

  • Inventory every API Manager, API Control Plane, Traffic Manager and Universal Gateway instance, including non-production and partner-facing ones, and confirm each is at or above the fixed update level for its version [1][7].
  • Scope the investigation from WSO2's advisory and the CWE-347 classification, not the KEV prose. Hunting only for uploaded files and web shells will miss this attack [1][3].
  • Hunt in gateway and Carbon access logs, reverse-proxy and WAF logs, and application audit history for administrator sessions without a matching identity provider login, unexpected JWT algorithm values where headers are logged, and bulk reads or exports of consumer keys and secrets [7]. Start at 13 September at the latest; where logs allow, start from April.
  • Where compromise cannot be ruled out, rotate consumer keys and secrets and the backend credentials the gateway holds, and review API definitions for changed endpoints [6].
  • Remove the Publisher, Admin and Carbon management interfaces from the internet [6].
  • Watch vendor repositories and advisory pages for the open-source components you run. For this flaw, the CVE feed lagged the public fix by almost four months [9][10].

The catalogue is a list of what to patch, and on that it is correct: CVE-2026-5430 is exploited and the deadline is real. It is a weaker guide to what to look for. Where its description and its own weakness classification disagree, the classification and the vendor's advisory are the better evidence, and here they point at forged identity, not dropped files.

Sources

Every R3KONX article cites its primary material. 16 sources, in order of first citation. Links open the original publication.

  1. Security Advisory WSO2-2026-5328/CVE-2026-5430 WSO2 · 2026-05-03
  2. CISA Adds Two Known Exploited Vulnerabilities to Catalog Cybersecurity and Infrastructure Security Agency (CISA) · 2026-09-24
  3. Known Exploited Vulnerabilities catalogue data (catalogue version 2026.09.24) CISA (cisagov/kev-data) · 2026-09-24
  4. Enterprises Warned of Attacks Exploiting WSO2 Vulnerability SecurityWeek · 2026-09-16
  5. Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens The Hacker News · 2026-09-16
  6. Exploitation attempts target WSO2 authentication bypass vulnerability Field Effect · 2026-09-17
  7. Hunt WSO2 CVE-2026-5430: JWT auth bypass Inception Security · 2026-09-22
  8. CISA Adds WSO2 and Adobe Flaws to KEV Catalog SecurityOnline · 2026-09-25
  9. CVE-2026-5430: CVSS 10.0, CRITICAL CVE Security · 2026-08-06
  10. Improve exception handling (carbon-apimgt pull request 13752) WSO2 on GitHub · 2026-04-12
  11. Improve advanced configuration tests (product-apim pull request 14167) WSO2 on GitHub · 2026-04-22
  12. RFC 8725: JSON Web Token Best Current Practices IETF (RFC Editor) · 2020-02-01
  13. CWE-347: Improper Verification of Cryptographic Signature MITRE · 2026-09-25
  14. Opportunistic Exploitation of WSO2 CVE-2022-29464 Rapid7 · 2022-04-22
  15. The Open Platform to Control APIs, AI, and MCP WSO2 · 2026-09-25
  16. Alert and Advisories National Cyber Security Agency (NACSA), Malaysia · 2026-06-30

This article was researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveats: the KEV entry was read from CISA's machine-readable catalogue as mirrored in CISA's own kev-data repository (catalogue version 2026.09.24); the NVD and cve.org record pages could not be rendered by this desk, so the CVE publication date of 6 August is carried from the CVE Security aggregator and corroborated only by SecurityWeek's “early August”. The EPSS figure is carried from the same aggregator. The watchTowr honeypot observations and the quotation from its analyst are carried from SecurityWeek and The Hacker News; this desk did not locate a watchTowr publication on the flaw. The link between the two GitHub pull requests and the vulnerability rests on WSO2's advisory naming them as the public fixes. Undated web pages are dated to the day this desk read them. No token construction or exploitation detail is reproduced. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.