• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-5430: pre-auth remote code execution in WSO2 Multiple Products

Remote attackers can bypass JWT verification and exploit a path traversal flaw to achieve remote code execution against WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway. CVE-2026-5430 affects multiple 4.x branches: Universal Gateway 4.5.0–before 4.5.0.57 and 4.6.0–before 4.6.0.21; Traffic Manager 4.5.0–before 4.5.0.56 and 4.6.0–before 4.6.0.21; API Control Plane 4.5.0–before 4.5.0.58 and 4.6.0–before 4.6.0.22; and API Manager 4.1.0–before 4.1.0.257, 4.2.0–before 4.2.0.197, 4.3.0–before 4.3.0.108 and 4.4.0–before 4.4.0.72. Exploitation requires network access and does not require valid credentials.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00588
CWE
CWE-347
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog with a federal remediation due date, and public exploit code exists, so prioritize patching or mitigations immediately.

What is CVE-2026-5430?

Remote attackers can bypass JWT verification and exploit a path traversal flaw to achieve remote code execution against WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway. CVE-2026-5430 affects multiple 4.x branches: Universal Gateway 4.5.0–before 4.5.0.57 and 4.6.0–before 4.6.0.21; Traffic Manager 4.5.0–before 4.5.0.56 and 4.6.0–before 4.6.0.21; API Control Plane 4.5.0–before 4.5.0.58 and 4.6.0–before 4.6.0.22; and API Manager 4.1.0–before 4.1.0.257, 4.2.0–before 4.2.0.197, 4.3.0–before 4.3.0.108 and 4.4.0–before 4.4.0.72. Exploitation requires network access and does not require valid credentials. The weakness is classified as CWE-347 (Improper Verification of Cryptographic Signature).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of WSO2 Multiple Products are affected?

BRANCHAFFECTEDFIXED
WSO2 Universal Gateway 4.x4.5.0 – before 4.5.0.574.5.0.57
WSO2 Universal Gateway 4.x4.6.0 – before 4.6.0.214.6.0.21
WSO2 Traffic Manager 4.x4.5.0 – before 4.5.0.564.5.0.56
WSO2 Traffic Manager 4.x4.6.0 – before 4.6.0.214.6.0.21
WSO2 API Control Plane 4.x4.5.0 – before 4.5.0.584.5.0.58
WSO2 API Control Plane 4.x4.6.0 – before 4.6.0.224.6.0.22
WSO2 API Manager 4.x4.1.0 – before 4.1.0.2574.1.0.257
WSO2 API Manager 4.x4.2.0 – before 4.2.0.1974.2.0.197
WSO2 API Manager 4.x4.3.0 – before 4.3.0.1084.3.0.108
WSO2 API Manager 4.x4.4.0 – before 4.4.0.724.4.0.72

Is CVE-2026-5430 being exploited?

CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on 2026-09-24; US federal agencies were required to address it by 2026-09-27.

How to fix CVE-2026-5430

  1. Upgrade to vendor-fixed releases: Universal Gateway to 4.5.0.57 or 4.6.0.21, Traffic Manager to 4.5.0.56 or 4.6.0.21, API Control Plane to 4.5.0.58 or 4.6.0.22, and API Manager to the listed fixed releases (4.1.0.257, 4.2.0.197, 4.3.0.108, 4.4.0.72).
  2. If immediate patching is not possible, restrict network exposure of affected services to trusted networks and firewall off public access.
  3. Follow vendor guidance for additional mitigations and enable enhanced logging and monitoring for suspicious JWT usage and file upload/path traversal attempts.

Frequently asked questions

Is CVE-2026-5430 being actively exploited?

Yes. CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on 2026-09-24, with a required remediation date of 2026-09-27 for federal agencies.

Which WSO2 versions are affected by CVE-2026-5430?

Multiple WSO2 4.x branches are affected: Universal Gateway, Traffic Manager, API Control Plane and API Manager in the version ranges listed by the vendor (see affected versions and fixed release numbers).

Is there a patch for CVE-2026-5430?

Yes. WSO2 published fixed releases for each affected branch; upgrade to the specific fixed versions provided by the vendor for your product branch.

Does CVE-2026-5430 require authentication?

No. The vulnerability can be exploited over the network without valid credentials.

References