WSO2 Product Security Update Advisory (CVE-2026-5430)
WSO2 Product Security Update Advisory (CVE-2026-5430)
A vulnerability (CVE-2026-5430) in the JWT authentication process of WSO2 products has been discovered, and a security update has been released. This vulnerability allows authentication bypass through tokens signed with unsupported algorithms.
Affected Products
- WSO2 API Control Plane 4.5.0.
- WSO2 API Control Plane 4.6.0.
- WSO2 API Manager 4.1.0.
- WSO2 API Manager 4.2.0.
- WSO2 API Manager 4.3.0.
- WSO2 API Manager 4.4.0.
- WSO2 API Manager 4.5.0.
- WSO2 API Manager 4.6.0.
- WSO2 Traffic Manager 4.5.0.
- WSO2 Traffic Manager 4.6.0.
- WSO2 Universal Gateway 4.5.0.
- WSO2 Universal Gateway 4.6.0.
Resolution
A patch has been provided via the latest update. Each product must be updated to the following Update Level or higher:
- WSO2 API Control Plane 4.5.0: Update Level 58 or higher.
- WSO2 API Control Plane 4.6.0: Update Level 22 or higher.
- WSO2 API Manager 4.1.0: Update Level 257 or higher.
- WSO2 API Manager 4.2.0: Update Level 197 or higher.
- WSO2 API Manager 4.3.0: Update Level 108 or higher.
- WSO2 API Manager 4.4.0: Update Level 72 or higher.
- WSO2 API Manager 4.5.0: Update Level 57 or higher.
- WSO2 API Manager 4.6.0: Update Level 21 or higher.
- WSO2 Traffic Manager 4.5.0: Update Level 56 or higher.
- WSO2 Traffic Manager 4.6.0: Update Level 21 or higher.
- WSO2 Universal Gateway 4.5.0: Update Level 57 or higher.
- WSO2 Universal Gateway 4.6.0: Update Level 21 or higher.
Notes
- Security Advisory WSO2-2026-5328/CVE-2026-5430.
- Improve exception handling – #13752.
- Improve advanced configuration tests – #14167.