CVE-2026-5430 is now in CISA’s Known Exploited Vulnerabilities catalog, with a September 27, 2026 remediation date for the applicable U.S. federal scope. But administrators should be careful with the vulnerability description: CISA’s current KEV text describes path traversal, unrestricted file upload and remote code execution, while WSO2’s own advisory identifies the same CVE as a JWT authentication bypass that can allow unauthorized access and potentially full account takeover.
Direct answer: use WSO2’s advisory as the controlling source for vulnerability mechanics and product remediation. Verify the exact WSO2 product, base version and installed update level against the fixed-level table below. Treat CISA’s KEV entry as confirmation that the vulnerability is being exploited and requires urgent prioritization, but do not describe CVE-2026-5430 as a confirmed path-traversal or unrestricted-file-upload RCE unless CISA or WSO2 resolves the current source conflict.
What changed with CVE-2026-5430?
The vulnerability itself is not newly discovered. WSO2 had already published its security advisory and fixes before the September KEV addition, and security researchers reported exploitation attempts during September.
The new state is that CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on September 24. That changes the operational priority: organizations should now treat the flaw as a known-exploited vulnerability and verify remediation rather than leaving it in normal patch backlog.

Why CISA and WSO2 describe the flaw differently
There is a material source discrepancy. CISA’s current KEV description calls CVE-2026-5430 a path-traversal vulnerability and says unrestricted file upload can lead to remote code execution.
WSO2’s controlling vendor advisory describes a different mechanism. It says some affected products can incorrectly accept JSON Web Tokens signed with unsupported algorithms. That authentication failure can allow unauthorized access and potentially full account takeover.
The CVE ID and WSO2 reference point to the JWT authentication-bypass advisory. TPS therefore uses WSO2’s description for the technical mechanics while preserving CISA’s conflicting wording as an unresolved metadata issue. The evidence reviewed does not establish why the KEV description differs or whether CISA intended to reference another WSO2 vulnerability.
What CVE-2026-5430 can allow
Under WSO2’s description, the security boundary failure is authentication. A forged or otherwise invalid JWT using an unsupported signing algorithm may be accepted when it should be rejected.
That can let an attacker access protected functionality without valid authentication and, depending on the affected deployment and privileges represented in the token, potentially obtain administrative access.
WSO2 rates the general vulnerability at CVSS 10.0, with a 9.8 score for single-tenant deployments.
Which WSO2 products and update levels fix CVE-2026-5430?
WSO2’s advisory identifies fixed update levels across API Manager, API Control Plane, Traffic Manager and Universal Gateway. Administrators should check the full product name, base version and installed update level rather than assuming that a major or minor product version alone proves remediation.
| WSO2 product | Base version | Fixed update level |
|---|---|---|
| API Control Plane | 4.6.0 | 22 or higher |
| API Control Plane | 4.5.0 | 58 or higher |
| API Manager | 4.6.0 | 21 or higher |
| API Manager | 4.5.0 | 57 or higher |
| API Manager | 4.4.0 | 72 or higher |
| API Manager | 4.3.0 | 108 or higher |
| API Manager | 4.2.0 | 197 or higher |
| API Manager | 4.1.0 | 257 or higher |
| Traffic Manager | 4.6.0 | 21 or higher |
| Traffic Manager | 4.5.0 | 56 or higher |
| Universal Gateway | 4.6.0 | 21 or higher |
| Universal Gateway | 4.5.0 | 57 or higher |
Subscription customers should use the WSO2 update mechanism to reach at least the applicable fixed update level. WSO2 also provides source-level fixes for community users; those users should apply the vendor-linked fix or move to an unaffected current release where appropriate.
Determine whether the deployment is API Manager, API Control Plane, Traffic Manager or Universal Gateway and record its base version.
Compare the installed update level with WSO2’s fixed level for that exact product and version. The base version alone is not enough.
Move to at least the fixed update level or apply WSO2’s source-level fix for the relevant community deployment.
If the deployment remained vulnerable during the reported exploitation window, review authentication and API activity for suspicious privileged sessions or forged-token behaviour and assess whether credentials or secrets may require rotation.
When was exploitation first reported?
Security researchers reported observing forged-JWT exploitation attempts beginning on September 13. The initial malicious request discussed publicly was sent to a honeypot running the wrong product, so that observation by itself did not prove a successful production compromise.
Researchers subsequently replayed the attacker’s approach against a product that was actually vulnerable and reproduced the authentication bypass. That supports the exploitability of the JWT flaw, but it is different from proving that a named production customer was successfully breached.
What could an attacker reach after a successful bypass?
Research reporting from reproduction testing described access to sensitive API-management information, including backend destinations, credentials, consumer keys and application secrets. Those findings show the potential consequence of administrative access, but TPS did not establish that those same assets were stolen from a confirmed real-world victim.
What should organizations investigate if they were unpatched?
Administrators should review the organization’s own authentication and API audit data for unexpected privileged sessions, suspicious JWT activity and access that does not match known users or expected administrative behaviour.
If the environment shows signs of unauthorized privileged access, the response should expand beyond patching. Assess credentials, API secrets and application keys that may have been accessible and follow the organization’s incident-response process. The reviewed public evidence does not provide a complete universal IOC set that can prove or disprove compromise for every WSO2 deployment.
What does the September 27 CISA deadline mean?
CISA’s KEV record assigns a remediation due date of September 27, 2026 for the applicable U.S. federal scope. It should not be described as a universal legal deadline for every organization.
For non-federal operators, the practical significance is still strong: KEV inclusion means CISA now treats CVE-2026-5430 as a known-exploited vulnerability, while WSO2 already provides concrete remediation levels.
Is ransomware using CVE-2026-5430?
CISA currently lists known ransomware-campaign use as Unknown. TPS did not establish a named ransomware group, threat actor or campaign tied to the vulnerability in the completed research.
Active exploitation and ransomware attribution are separate evidence states and should not be collapsed.
What remains unresolved?
The most important unresolved point is the mismatch between CISA’s KEV vulnerability description and WSO2’s vendor advisory. TPS did not find primary evidence explaining whether the CISA wording is a catalog error, refers to another WSO2 flaw or will be corrected.
The reviewed evidence also does not establish the number of production victims, geographic scope of successful compromise, attacker identity, ransomware involvement or confirmed theft of credentials and secrets from named real-world organizations.
What happens next?
The next verified checkpoint is CISA’s September 27 remediation milestone. This article should also be updated if CISA changes the KEV description, WSO2 revises affected products or fixed update levels, new indicators or threat-hunting guidance appear, or credible reporting establishes a campaign, victim set or ransomware connection.
Verification note
TPS reconciled WSO2’s vendor advisory with CISA’s KEV state and current exploitation reporting. WSO2 is treated as the controlling source for CVE-2026-5430 mechanics and fixed update levels; CISA is treated as the controlling source for KEV status and the September 27 remediation date. The conflicting vulnerability descriptions remain explicitly unresolved rather than being silently merged.