Exploited in the wild API Manager auth-bypass API Control Plane WSO2 cryptography
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
CVE Tools coverage
Active exploitation attempts are targeting CVE-2026-5430, a JWT signature-validation bypass in WSO2 API Control Plane 4.6.0 and 4.5.0; WSO2 API Manager 4.6.0, 4.5.0, 4.4.0, 4.3.0, 4.2.0, and 4.1.0; WSO2 Traffic Manager 4.6.0 and 4.5.0; and WSO2 Universal Gateway 4.6.0 and 4.5.0. Attackers can submit forged tokens with administrator privileges to bypass authentication, potentially exposing API backends, credentials, consumer keys, secrets, and internal services; users should apply WSO2's available fixes immediately.