WSO2 Product Security Update Advisory (CVE-2026-5430)

WSO2 Product Security Update Advisory (CVE-2026-5430)

WSO2 Product Security Update Advisory (CVE-2026-5430)


A vulnerability (CVE-2026-5430) in the JWT authentication process of WSO2 products has been discovered, and a security update has been released. This vulnerability allows authentication bypass through tokens signed with unsupported algorithms.

Affected Products


  • WSO2 API Control Plane 4.5.0.
  • WSO2 API Control Plane 4.6.0.
  • WSO2 API Manager 4.1.0.
  • WSO2 API Manager 4.2.0.
  • WSO2 API Manager 4.3.0.
  • WSO2 API Manager 4.4.0.
  • WSO2 API Manager 4.5.0.
  • WSO2 API Manager 4.6.0.
  • WSO2 Traffic Manager 4.5.0.
  • WSO2 Traffic Manager 4.6.0.
  • WSO2 Universal Gateway 4.5.0.
  • WSO2 Universal Gateway 4.6.0.

Resolution


A patch has been provided via the latest update. Each product must be updated to the following Update Level or higher:

  • WSO2 API Control Plane 4.5.0: Update Level 58 or higher.
  • WSO2 API Control Plane 4.6.0: Update Level 22 or higher.
  • WSO2 API Manager 4.1.0: Update Level 257 or higher.
  • WSO2 API Manager 4.2.0: Update Level 197 or higher.
  • WSO2 API Manager 4.3.0: Update Level 108 or higher.
  • WSO2 API Manager 4.4.0: Update Level 72 or higher.
  • WSO2 API Manager 4.5.0: Update Level 57 or higher.
  • WSO2 API Manager 4.6.0: Update Level 21 or higher.
  • WSO2 Traffic Manager 4.5.0: Update Level 56 or higher.
  • WSO2 Traffic Manager 4.6.0: Update Level 21 or higher.
  • WSO2 Universal Gateway 4.5.0: Update Level 57 or higher.
  • WSO2 Universal Gateway 4.6.0: Update Level 21 or higher.

Notes


  • Security Advisory WSO2-2026-5328/CVE-2026-5430.
  • Improve exception handling – #13752.
  • Improve advanced configuration tests – #14167.