Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-5430
WSO2 WSO2 Universal Gateway — Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C H H H 10.0 .0059 46.2 YES
AFFECTED
Product Versions Fixed
WSO2 Universal Gateway 4.5.0 – —
WSO2 Traffic Manager 4.5.0 – —
WSO2 API Control Plane 4.5.0 – —
WSO2 API Manager 4.1.0 – —
WSO2 Carbon API Manager Rest API Utility 9.20.74 – 9.33.106
TIMELINE
Apr 2 Reserved by WSO2
Aug 6 Published (CNA: WSO2)
Sep 24 ADDED TO KEV — CVE-2026-5430 (WSO2 Universal Gateway). Remediation due September 27, 2026.
Sep 28 DUE DATE PASSED — CVE-2026-5430 (WSO2 Universal Gateway). CISA remediation deadline was September 27, 2026; still in catalog.
Description
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.
Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| April 2, 2026 | Reserved | Reserved by WSO2 |
| August 6, 2026 | Published | Published (CNA: WSO2) |
| September 24, 2026 | KEV ADDED | ADDED TO KEV — CVE-2026-5430 (WSO2 Universal Gateway). Remediation due September 27, 2026. |
| September 28, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-5430 (WSO2 Universal Gateway). CISA remediation deadline was September 27, 2026; still in catalog. |
Affected
Affected products and packages — 5 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| WSO2 | WSO2 Universal Gateway | — | 4.5.0 | — |
| WSO2 | WSO2 Traffic Manager | — | 4.5.0 | — |
| WSO2 | WSO2 API Control Plane | — | 4.5.0 | — |
| WSO2 | WSO2 API Manager | — | 4.1.0 | — |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | — | 9.20.74 | 9.33.106 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-5430 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.