U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-5430

Change History

New CVE Received from WSO2 LLC 8/06/2026 4:16:33 AM

Action Type Old Value New Value
Added Description

                  
                
              
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.

Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Added CVSS V3.1

                  
                
              
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Added CWE

                  
                
              
CWE-347
Added Reference

                  
                
              
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/
Added Affected

                  
                
              
[{"vendor":"WSO2","product":"WSO2 Universal Gateway","defaultStatus":"unaffected","versions":[{"version":"4.5.0","lessThan":"4.5.0.57","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.21","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Traffic Manager","defaultStatus":"unaffected","versions":[{"version":"4.5.0","lessThan":"4.5.0.56","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.21","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 API Control Plane","defaultStatus":"unaffected","versions":[{"version":"4.5.0","lessThan":"4.5.0.58","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.22","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 API Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.1.0","versionType":"custom","status":"unknown"},{"version":"4.1.0","lessThan":"4.1.0.257","versionType":"custom","status":"affected"},{"version":"4.2.0","lessThan":"4.2.0.197","versionType":"custom","status":"affected"},{"version":"4.3.0","lessThan":"4.3.0.108","versionType":"custom","status":"affected"},{"version":"4.4.0","lessThan":"4.4.0.72","versionType":"custom","status":"affected"},{"version":"4.5.0","lessThan":"4.5.0.57","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.21","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Carbon API Manager Rest API Utility","defaultStatus":"unknown","packageName":"org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util","versions":[{"version":"9.20.74","lessThan":"9.20.74.401","versionType":"custom","status":"affected"},{"version":"9.28.116","lessThan":"9.28.116.417","versionType":"custom","status":"affected"},{"version":"9.29.120","lessThan":"9.29.120.236","versionType":"custom","status":"affected"},{"version":"9.30.67","lessThan":"9.30.67.167","versionType":"custom","status":"affected"},{"version":"9.31.86","lessThan":"9.31.86.158","versionType":"custom","status":"affected"},{"version":"9.32.147","lessThan":"9.32.147.59","versionType":"custom","status":"affected"},{"version":"9.33.106","lessThanOrEqual":"*","versionType":"custom","status":"unaffected"}]}]