CVE-2026-5430: WSO2 API Manager auth bypass rated CVSS 10.0
WSO2 patched CVE-2026-5430 in API Manager in April 2026, but exploitation was observed in September after CISA added it to the KEV catalog. The CVSS 10.0 flaw lets an unauthenticated attacker bypass JWT signature validation and reach administrative functions.
- CVSS 10.0 in multi-tenant deployments and 9.8 in single-tenant
- Patch shipped in April 2026, exploitation seen five months later
- Affects API Manager, API Control Plane, Traffic Manager and Universal Gateway
- Suspected exposure requires rotating consumer keys and secrets
Read next
Security