
Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account takeover.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-5430
WSO2 API Manager 4.5.0 — WSO2
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.
| CVE | CVE-2026-5430 · CVE.org |
| CWE | CWE-347 |
| CVSS | Critical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Product | WSO2 API Manager |
| Affected | all versions through 4.5.0 (inclusive) |
| Patched | 4.5.0 update 57 (community: carbon-apimgt PR 13752) and later |
| Auth | unauthenticated (see source map) |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only · vendor/client disclosure pack, not a scanner |
carbon-apimgt JWTUtil.verifyTokenSignature and OAuthAuthenticationInterceptor. Patch PR 13752 throws OAuthAuthenticationInterceptorException. Vendor test product-apim PR 14167 forges HS256 admin JWT.
GET/api/am/admin/v4/tenant-configGET /api/am/admin/v4/tenant-config Authorization Bearer HS256 JWT (no kid)OAuthAuthenticationInterceptor extracts JWT (token contains '.')OAuthJwtAuthenticatorImpl.validateJWTToken -> JWTValidatorImpl.validateSignatureJWTUtil.verifyTokenSignature(jwt, alias) throws APIManagementException for HS256pre-patch interceptor catch logs and returns; request proceeds as claimed adminUnauthenticated 200 JSON from /api/am/admin/v4/tenant-config with forged HS256 Bearer. Control GET without token is 401.
Do this first: Update WSO2 API Manager to 4.5.0 update 57 (community: carbon-apimgt PR 13752) or newer.
Verify after upgrade
CVE-2026-5430-Abraxas-Labs.py against the patched build: the mapped witness must not appear.If you cannot update immediately
Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.
python3 CVE-2026-5430-Abraxas-Labs.py
Success is the witness above in the response body. Generic 200 HTML is not it.
Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.
cd lab
docker compose up --force-recreate
Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.
# CVE-2026-5430 / WSO2-2026-5328
CWE: CWE-347
CVSS: Critical 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (vendor). Single-tenant 9.8. CISA KEV 2026-09-24.
## Description
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. An HS256 token with no kid makes `JWTUtil.verifyTokenSignature` throw; pre-patch `OAuthAuthenticationInterceptor` swallows `APIManagementException` and continues, so the Admin/Publisher REST call runs with the token claims (including `sub=admin`).
## Product
WSO2 API Manager 4.5.0 GA Docker Hub image (no Updates). Same carbon-apimgt on API Control Plane 4.5.0/4.6.0, API Manager 4.1.0-4.6.0, Traffic Manager 4.5.0/4.6.0, Universal Gateway 4.5.0/4.6.0.
This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.
This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.