Five Months After the Patch, WSO2’s JWT Bypass Hit CISA’s KEV — With a Three-Day Fix Deadline

On September 24, CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog and gave federal agencies until September 27 to remediate — a three-day window that signals how seriously the agency takes active exploitation. The flaw lets an unauthenticated attacker forge a JSON Web Token signed with an algorithm the server does not even support, and have it accepted as a trusted admin session. The patch has existed since April.

The affected products are the exact infrastructure that sits between the outside world and internal APIs: WSO2 API Manager 4.1.0 through 4.6.0, plus the API Control Plane, Traffic Manager, and Universal Gateway. NVD rates it CVSS 10.0 when scope changes and 9.8 in single-tenant deployments (AV:N/AC:L/PR:N/UI:N — network-accessible, no privileges, no user interaction), under CWE-347, improper verification of cryptographic signature. The discoverer credited is the Hacktron Team, and the vendor advisory is WSO2-2026-5328, published in May.

The exploitation timeline is the story

WatchTowr’s global honeypot network captured the first in-the-wild exploitation attempt on September 13: forged JWTs arriving with administrator privileges baked in. Principal threat intelligence specialist Yordan Ganchev told SecurityWeek the attacker actually targeted the wrong product in the honeypot — but when WatchTowr replayed the payload against the real one, it worked. The CVE record itself was only published on August 6, and Ganchev noted that technical details still are not public; WatchTowr reproduced the flaw from the vendor’s patch alone. His dry summary: the only mystery is what took everyone else so long.

So the full arc runs: patched in April, advisory in May, CVE record in August, exploitation in September, KEV listing eleven days after the first honeypot hit. Five months of patch availability bought no safety for anyone who did not apply it. That is the same shape as the LiteLLM KEV entry — except here the vulnerable population is not an AI proxy but the API gateway layer of banks, government agencies, telecoms, and logistics firms. WSO2 counts nearly a thousand enterprise customers in those sectors, plus thousands more open-source and OEM deployments.

Why this one matters for agent deployments

An API gateway is, by design, a machine that intercepts requests on their way to internal systems and holds the credentials for everything behind it. Ganchev’s description of what the forged token yields is worth quoting in full: access to every API backend endpoint and its credentials, consumer keys, and secrets for every registered application. His characterisation of the compromised box — “lateral movement-as-a-service” — is precise. A gateway that will mint trusted sessions from self-signed tokens is not one compromised endpoint; it is a tap on all of them, plus the keys to walk sideways into internal services.

That is directly relevant to anyone routing agent traffic through this layer. Agents authenticate to enterprise APIs through gateways exactly like these, and their credentials — service-account tokens, consumer secrets, backend keys — are the material sitting behind the forged-JWT door. An attacker who forges admin does not need to phish your agent or poison its tools; they collect the keys the agent itself uses.

One catalog, two descriptions

There is a feed-hygiene footnote here, and regular readers will recognise the pattern from the mcp-remote CVE batch and the DBHub advisories. CISA’s KEV entry titles CVE-2026-5430 a “Path Traversal Vulnerability” whose description reads “unrestricted file upload … lead to remote code execution.” NVD’s record — same CVE ID, same vendor advisory link — describes JWT authentication accepting unsupported algorithms leading to unauthorized access and admin compromise, with CWE-347. Both entries point at WSO2-2026-5328.

We are not adjudicating whether the advisory bundles multiple issues or one entry mislabels the flaw. The operational point is narrower: if your triage reads only the KEV one-liner, you will hunt for file-upload exploitation; if you read only NVD, you will hunt for forged tokens. The observed in-the-wild activity is forged JWTs. Hunt for that — anomalous administrator sessions with no corresponding identity-provider issuance, JWTs carrying algorithms your configuration never selected — and patch per the vendor advisory regardless of which description your scanner shows. CISA also flags the CVE as known ransomware-associated, which is a second reason the three-day deadline is real.

What to do

  • Patch to the fixed update levels now. API Manager 4.6.0 needs update level 21, 4.5.0 level 57, 4.4.0 level 72, 4.3.0 level 108, 4.2.0 level 197, 4.1.0 level 257, with corresponding levels for Control Plane, Traffic Manager, and Universal Gateway. Community users have the carbon-apimgt and product-apim pull requests. The federal deadline is September 27; everyone else should treat it as already passed.
  • Assume pre-patch admin sessions are compromised. A forged token yields administrator privileges, so review admin account activity and access logs back to at least early September — and rotate every consumer key, consumer secret, and backend credential registered on the gateway, since those were readable to anyone holding a forged token.
  • Hunt the JWT layer, not just the file layer. Look for accepted tokens signed with algorithms outside your configured set, admin sessions with no IdP-side issuance, and unexpected administrator account changes. The KEV “path traversal” wording should not narrow your detection to upload paths.
  • Inventory agent credentials behind the gateway. Service-account tokens and API keys your agents use against backends fronted by WSO2 were within the blast radius. Rotate them and scope them down — a token that can only call the endpoints its task needs is worth less to whoever holds the next forged one.
  • Do not rely on “patched in April” as assurance. WatchTowr reproduced this from the patch diff alone, with no public technical details. Anyone else with the diff and an afternoon could do the same. Unpatched instances are not obscure; they are described, diffable, and now actively probed.

The uncomfortable arithmetic: a maximum-severity authentication bypass in the box that holds every API secret, patched for five months, exploited within eleven days of first observation, with a three-day federal deadline and a ransomware flag. The patch existed. The inventory and the patching did not. For agent operators, the lesson is that the gateway is part of the agent’s trust boundary whether you drew it that way or not — forge the gateway’s trust and every credential behind it changes hands.

Sources: