Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-5430 — Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account takeover. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-5430
Vulnerability AnalysisExploitationWeb Application ExploitationSecurity VirtualizationCryptographyPenetration TestingAuthenticationAPI SecurityLabs & Practice
GitHubabraxas/cve-2026-5430

CVE-2026-5430

Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account takeover.

112 days agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Abraxas Labs — CVE-2026-5430

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  CVE-2026-5430

CVE-2026-5430

WSO2 API Manager 4.5.0 — WSO2

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.

CVECVE-2026-5430 · CVE.org
CWECWE-347
CVSSCritical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductWSO2 API Manager
Affectedall versions through 4.5.0 (inclusive)
Patched4.5.0 update 57 (community: carbon-apimgt PR 13752) and later
Authunauthenticated (see source map)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only · vendor/client disclosure pack, not a scanner

Advisory (from the source map)

carbon-apimgt JWTUtil.verifyTokenSignature and OAuthAuthenticationInterceptor. Patch PR 13752 throws OAuthAuthenticationInterceptorException. Vendor test product-apim PR 14167 forges HS256 admin JWT.


Entry

  • Method: GET
  • Path: /api/am/admin/v4/tenant-config
  • Router: Unauthenticated Admin/Publisher REST. OAuthAuthenticationInterceptor JWT path. JWTUtil.verifyTokenSignature alias overload throws on non-RSA alg; interceptor used to swallow that and continue.
  • Notes: Unauthenticated CVE-2026-5430 CWE-347 WSO2 API Manager 4.5.0 GA. Witness: 200 JSON on admin tenant-config. Control without token is 401. Not a reverse shell.

Call chain

  • GET /api/am/admin/v4/tenant-config Authorization Bearer HS256 JWT (no kid)
  • OAuthAuthenticationInterceptor extracts JWT (token contains '.')
  • OAuthJwtAuthenticatorImpl.validateJWTToken -> JWTValidatorImpl.validateSignature
  • JWTUtil.verifyTokenSignature(jwt, alias) throws APIManagementException for HS256
  • pre-patch interceptor catch logs and returns; request proceeds as claimed admin

Lab preconditions

  • WSO2 API Manager / ACP / TM / Universal Gateway on an affected GA line without the update-level patch
  • management REST reachable (9443)

Witness

Unauthenticated 200 JSON from /api/am/admin/v4/tenant-config with forged HS256 Bearer. Control GET without token is 401.

Not success

  • 401 after carbon-apimgt PR 13752 / listed update levels
  • reverse shell
  • RCE payload

Patch / remediation

Do this first: Update WSO2 API Manager to 4.5.0 update 57 (community: carbon-apimgt PR 13752) or newer.

Verify after upgrade

  • Re-run CVE-2026-5430-Abraxas-Labs.py against the patched build: the mapped witness must not appear.
  • Confirm the vendor advisory / changeset in the deployed tree (see references).
  • A WAF signature is delay, not a patch.

If you cannot update immediately

  • Disable or isolate the affected component.
  • Hunt for the witness condition on production (new privileged users, unexpected files, injected rows — whatever this CVE's map names).

Reproduction (authorized lab)

Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.

root@kitploit:~
python3 CVE-2026-5430-Abraxas-Labs.py

Success is the witness above in the response body. Generic 200 HTML is not it.


Lab images

Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.

  • lab/docker-compose.yml
  • lab/Dockerfile
root@kitploit:~
cd lab
docker compose up --force-recreate

Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.


References

  • CVE-2026-5430 · NVD

  • CVE-2026-5430 · CVE.org

  • security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/

  • github.com/wso2/carbon-apimgt/pull/13752

  • github.com/wso2/product-apim/pull/14167

  • www.cve.org/CVERecord?id=CVE-2026-5430

  • www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-5430

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


Records (structured)

root@kitploit:~
# CVE-2026-5430 / WSO2-2026-5328

CWE: CWE-347
CVSS: Critical 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (vendor). Single-tenant 9.8. CISA KEV 2026-09-24.

## Description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. An HS256 token with no kid makes `JWTUtil.verifyTokenSignature` throw; pre-patch `OAuthAuthenticationInterceptor` swallows `APIManagementException` and continues, so the Admin/Publisher REST call runs with the token claims (including `sub=admin`).

## Product

WSO2 API Manager 4.5.0 GA Docker Hub image (no Updates). Same carbon-apimgt on API Control Plane 4.5.0/4.6.0, API Manager 4.1.0-4.6.0, Traffic Manager 4.5.0/4.6.0, Universal Gateway 4.5.0/4.6.0.

License

This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.


Disclaimer

This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool