boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-5430

WSO2 WSO2 Universal Gateway — Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0059   46.2   YES
AFFECTED
  Product                                   Versions   Fixed
  WSO2 Universal Gateway                    4.5.0 –    —
  WSO2 Traffic Manager                      4.5.0 –    —
  WSO2 API Control Plane                    4.5.0 –    —
  WSO2 API Manager                          4.1.0 –    —
  WSO2 Carbon API Manager Rest API Utility  9.20.74 –  9.33.106
TIMELINE
  Apr 2   Reserved by WSO2
  Aug 6   Published (CNA: WSO2)
  Sep 24  ADDED TO KEV — CVE-2026-5430 (WSO2 Universal Gateway). Remediation due September 27, 2026.
  Sep 28  DUE DATE PASSED — CVE-2026-5430 (WSO2 Universal Gateway). CISA remediation deadline was September 27, 2026; still in catalog.
CWE-347 · CNA: WSO2 · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due September 27, 2026

Description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
April 2, 2026ReservedReserved by WSO2
August 6, 2026PublishedPublished (CNA: WSO2)
September 24, 2026KEV ADDEDADDED TO KEV — CVE-2026-5430 (WSO2 Universal Gateway). Remediation due September 27, 2026.
September 28, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-5430 (WSO2 Universal Gateway). CISA remediation deadline was September 27, 2026; still in catalog.

Affected

Affected products and packages — 5 rows
VendorProduct / PackageEcosystemVersion introducedFixed
WSO2WSO2 Universal Gateway—4.5.0—
WSO2WSO2 Traffic Manager—4.5.0—
WSO2WSO2 API Control Plane—4.5.0—
WSO2WSO2 API Manager—4.1.0—
WSO2WSO2 Carbon API Manager Rest API Utility—9.20.749.33.106

Weaknesses

CWE-347

References (2)

Related

Authoritative record: CVE-2026-5430 at cve.org

Vendors: wso2

Weaknesses: CWE-347

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-5430 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.