LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 24, 2026
CVSS 10.0 · Critical⚠ Actively exploited (CISA KEV)
10.0
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Sep 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on Sep 24, 2026, with a federal patch deadline of Sep 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

CVE-2026-5430 is a path traversal weakness affecting multiple WSO2 products, including API Control Plane, API Manager, Traffic Manager, and Universal Gateway. In plain terms, flawed handling of file paths can let an attacker place files where they should not, which the public description links to unrestricted file upload and possible remote code execution. For teams running these components as API and traffic infrastructure, that combination matters because compromise of a gateway or manager often means broad access to APIs, tokens, and backend services.

Public detail is limited to the class of issue and the products named above. Exact affected builds, scores, and exploitation mechanics must be confirmed against the vendor advisory. Known ransomware use is not documented for this CVE.

How it works

The record lists weakness CWE-347 alongside a path traversal vulnerability. Path traversal flaws arise when software takes attacker-influenced path or filename input and does not fully normalize or constrain it before using it in filesystem operations. An attacker who can reach the vulnerable interface may craft requests that escape the intended directory, write or overwrite files in sensitive locations, or achieve unrestricted upload behavior. On products that process uploads, deploy artifacts, or serve configuration and plugins, that can escalate to code execution if a writable location is later interpreted or executed by the runtime.

Do not assume a specific request format, endpoint, or payload. Treat the abuse model as: network-reachable component accepts path-related input → insufficient validation → file write outside the allowed tree → possible RCE depending on product role and configuration. Confirm the precise trigger and preconditions only from the vendor advisory.

Am I affected? How to find it in your systems

WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway commonly appear in enterprise API platforms, edge or DMZ traffic layers, and internal service meshes. Inventory any hosts, containers, or cloud images running these product names or related WSO2 distributions.

If you cannot map a version confidently, assume in-scope until the advisory clears it.

How to remediate

Patch first. Apply the vendor updates and mitigations named in the official advisory for CVE-2026-5430 across API Control Plane, API Manager, Traffic Manager, Universal Gateway, and any other WSO2 products the vendor lists. Follow CISA’s direction to apply mitigations per vendor instructions, align with BOD 26-04 risk-based prioritization and forensics triage expectations, and for cloud or managed instances follow applicable BOD 26-04 cloud guidance—or discontinue use if mitigations are unavailable.

If you can't patch immediately

Reduce reachability and blast radius until the vendor fix is live.

Stakeholders remain responsible for evaluating each asset’s internet exposure and meeting BOD 26-04 patching expectations.

If your data may have been exposed

Actively exploited vulnerabilities of this severity class can lead to full host compromise, credential theft, and downstream data access even when ransomware use is not documented. If these WSO2 components were reachable and unpatched during a suspected attack window, treat them as potentially breached: isolate, preserve forensic evidence per your and CISA triage guidance, rotate secrets and tokens issued through the platform, and review API traffic and data stores the gateway could reach. You can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts already appear in public breach collections, then prioritize password resets and MFA for any hits.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWSO2 · Multiple Products
WeaknessCWE-347
CVSS base score10.0 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
PublishedAug 6, 2026
Added to CISA KEVSep 24, 2026
Federal patch deadlineSep 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities