WSO2 CVE-2026-5430 – Actively Exploited JWT Authentication Bypass

Threat Overview

CVE-2026-5430 is a critical authentication-bypass vulnerability in WSO2 API products. WSO2’s advisory describes a JWT validation flaw in which tokens signed with unsupported algorithms can be accepted, potentially allowing unauthenticated access and administrative account takeover. WSO2 rates the issue CVSS 10.0, or 9.8 in single-tenant deployments. CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on September 24, 2026, confirming exploitation in the wild.

There is an important source discrepancy: CISA’s KEV text describes path traversal/unrestricted file upload leading to RCE, while WSO2’s vendor advisory and CVE record describe improper cryptographic-signature verification/JWT authentication bypass. This hunt follows WSO2’s technical description and does not invent a path-traversal exploit path.

References

Impacted Systems

WSO2 API Control Plane 4.6.0 and 4.5.0; API Manager 4.6.0 through 4.1.0; Traffic Manager 4.6.0 and 4.5.0; Universal Gateway 4.6.0 and 4.5.0. Network-reachable JWT-authenticated interfaces are the relevant exposure. Customers should apply the vendor-specified update level or published fix for their deployed branch.

Why this matters

CISA KEV inclusion changes this from a critical theoretical exposure to a confirmed exploited vulnerability. WSO2 API infrastructure can sit at a high-trust boundary and may expose administrative functions, API credentials, tokens, and backend access if authentication is bypassed.

Exploitation Status

Confirmed exploitation in the wild based on CISA KEV inclusion on September 24. Public authoritative sources reviewed did not identify a specific threat actor, ransomware group, victim set, or reliable exploit-specific IOC list.

What this hunt looks for

Unusual JWT/authentication events, rare authentication sources, Java child-process execution, Java-created scripts or executables, persistence activity, and new outbound destinations from WSO2 hosts.

Required logs

WSO2 application/authentication logs forwarded to Sentinel, Linux Syslog, and Microsoft Defender endpoint telemetry where available.

First Pass – WSO2 JWT and Authentication Events

Syslog
| where TimeGenerated >= ago(30d)
| where SyslogMessage has_any ("JWT","jwt","authentication","Authentication")
| where SyslogMessage has_any ("algorithm","signature","admin","administrator","unauthorized","authenticated")
| project TimeGenerated,Computer,HostName,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc

Rare Sources in WSO2 Authentication Logs

let Baseline=Syslog
| where TimeGenerated between (ago(30d)..ago(7d))
| where SyslogMessage has_any ("JWT","jwt","authentication","Authentication")
| extend SourceIP=extract(@"\b(?:\d{1,3}\.){3}\d{1,3}\b",0,SyslogMessage)
| where isnotempty(SourceIP)
| summarize by Computer,SourceIP;
Syslog
| where TimeGenerated >= ago(7d)
| where SyslogMessage has_any ("JWT","jwt","authentication","Authentication")
| extend SourceIP=extract(@"\b(?:\d{1,3}\.){3}\d{1,3}\b",0,SyslogMessage)
| where isnotempty(SourceIP)
| join kind=leftanti Baseline on Computer,SourceIP
| project TimeGenerated,Computer,HostName,SourceIP,ProcessName,SyslogMessage
| order by TimeGenerated desc

Java Spawning Shells on WSO2 Hosts

DeviceProcessEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("java","java.exe")
| where FileName in~ ("sh","bash","dash","cmd.exe","powershell.exe","pwsh.exe","python","python3","curl","wget")
| project Timestamp,DeviceName,AccountName,InitiatingProcessCommandLine,FileName,ProcessCommandLine,SHA256
| order by Timestamp desc

Java-Created Scripts and Executables

DeviceFileEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("java","java.exe")
| where ActionType in~ ("FileCreated","FileModified")
| where FileName endswith ".sh" or FileName endswith ".py" or FileName endswith ".ps1" or FileName endswith ".jar" or FileName endswith ".class" or FileName endswith ".exe"
| project Timestamp,DeviceName,ActionType,FileName,FolderPath,SHA256,InitiatingProcessCommandLine
| order by Timestamp desc

Java Outbound Network Activity

DeviceNetworkEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("java","java.exe")
| project Timestamp,DeviceName,InitiatingProcessAccountName,InitiatingProcessCommandLine,RemoteUrl,RemoteIP,RemotePort
| order by Timestamp desc

New Java Outbound Destinations

let Baseline=DeviceNetworkEvents
| where Timestamp between (ago(30d)..ago(7d))
| where InitiatingProcessFileName in~ ("java","java.exe")
| summarize by DeviceId,RemoteIP,RemoteUrl;
DeviceNetworkEvents
| where Timestamp >= ago(7d)
| where InitiatingProcessFileName in~ ("java","java.exe")
| join kind=leftanti Baseline on DeviceId,RemoteIP,RemoteUrl
| project Timestamp,DeviceName,InitiatingProcessCommandLine,RemoteUrl,RemoteIP,RemotePort
| order by Timestamp desc

Java-Initiated Persistence Activity

DeviceProcessEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("java","java.exe","sh","bash")
| where FileName in~ ("systemctl","crontab","at","schtasks.exe","sc.exe")
| project Timestamp,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by Timestamp desc

WSO2 High-Severity Syslog Events

Syslog
| where TimeGenerated >= ago(30d)
| where SyslogMessage has_any ("WSO2","wso2","API Manager","API Control Plane","Universal Gateway","Traffic Manager")
| where SeverityLevel in ("emerg","alert","crit","err") or SyslogMessage has_any ("ERROR","FATAL","Exception")
| project TimeGenerated,Computer,HostName,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc

Detection Notes

The vendor does not publish a reliable exploit-specific IOC set. The authentication queries depend on WSO2 logs being forwarded into Syslog with useful authentication context. Java behavior is broader because successful authentication bypass may resemble legitimate application activity until post-compromise actions occur. Java child shells, persistence, and new destinations are higher-signal follow-ups. The hunt intentionally avoids speculative path-traversal or file-upload indicators because of the discrepancy between CISA and WSO2 descriptions.

Leave a comment