Active Attacks Exploit Patched WSO2 JWT Flaw

WatchTowr reports attackers are using forged JWTs to exploit WSO2 CVE-2026-5430, bypassing authentication and accessing API backends and credentials; first attempt seen Sept. 13.

Security firm WatchTowr reported that threat actors are actively exploiting CVE-2026-5430, a vulnerability in WSO2 software patched in April, to bypass JWT authentication and access API backends, credentials and registered application secrets.

WatchTowr recorded the first exploitation attempt against a honeypot on Sept. 13. The firm reproduced the exploit using the vendor patch and identified the attacker’s method as the use of forged JSON Web Tokens that grant broad access to targeted systems.

The flaw affects multiple WSO2 products, including API Manager, API Control Plane, Traffic Manager and Universal Gateway. WSO2 published an advisory in May warning that a token signed with an unsupported algorithm can allow authentication to be bypassed, potentially enabling unauthorized access and account takeover. The vulnerability has a maximum CVSS score of 10 and a formal CVE entry appeared in early August; detailed public technical analysis remains limited. The incident follows another critical Fortinet JWT authentication bypass disclosed this month, showing how token-validation failures can expose privileged enterprise access across unrelated platforms.

Yordan Ganchev, principal threat intelligence specialist at WatchTowr, reported that the forged token provided access to every API backend endpoint and exposed credentials, consumer keys and secrets for registered applications. He added that the platform’s role in routing API requests increases the potential impact if exploited.

WatchTowr also noted that an initial attacker targeted the wrong product in the honeypot, but when researchers replayed the payload against the correct WSO2 component the exploit succeeded. Reproducing the issue from the vendor patch was straightforward, according to the firm.

WSO2 is used by nearly 1,000 enterprise customers across sectors including banking, government, telecom and logistics, and is widely deployed through open source channels and OEM partners. Organizations running affected, unpatched WSO2 installations should apply vendor updates and follow WSO2 guidance, as detection and mitigation currently depend on the vendor patch and advisories.

Articles by this author