Knox CVE Database
/
CVE-2026-5430
Critical
10.0

CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

Added to the CISA KEV catalog:
September 24, 2026

Overview

WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway contain an improper JWT signature verification flaw that allows a remote, unauthenticated attacker to bypass authentication entirely. By submitting a token signed with an algorithm outside the configured set, an attacker can pass signature validation and gain unauthorized access, potentially including administrative account takeover. The KEV entry additionally notes path traversal and unrestricted file upload capabilities that can lead to remote code execution, suggesting the authentication bypass may open further exploitation paths.

Vulnerability details

Affected vendor
WSO2
Affected product
Multiple Products
Weakness type (CWE)
CWE-347

CWE-347 describes a failure to properly verify cryptographic signatures on trusted tokens. In affected WSO2 products, the JWT authentication layer does not restrict accepted signing algorithms to those explicitly configured. When a token arrives signed with an unsupported or weak algorithm, the verification logic accepts it as valid rather than rejecting it. This means the cryptographic guarantee that the token was issued by a trusted party is never actually checked, collapsing the authentication boundary for any endpoint that relies on JWT-based access control.


An attacker with no prior credentials or account sends a crafted JWT token, signed with an algorithm outside the configured set, directly to an affected product's authentication endpoint over the network. No preconditions are stated. On acceptance, the attacker gains unauthorized access to the system, with the potential to compromise administrative accounts and achieve full account takeover. The CISA KEV entry further notes that path traversal and unrestricted file upload capabilities are present, which may allow an attacker who has bypassed authentication to upload malicious files and achieve remote code execution.

Severity and impact

10.0
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor authentication logs for JWT validation successes where the token's algorithm header does not match the product's configured allowed algorithms. A mismatch that results in a granted session is a strong indicator of exploitation.
  • Audit administrative account activity for sessions with no corresponding legitimate login event or originating from unexpected source addresses, particularly short-lived sessions that immediately perform privileged operations.
  • On systems running affected versions, inspect file upload directories and application deployment paths for unexpected files or artifacts deposited without a corresponding authorized deployment workflow.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 27, 2026

Additional hardening

  • Upgrade WSO2 API Manager to 4.1.0.257, 4.2.0.197, 4.3.0.108, 4.4.0.72, 4.5.0.57, or 4.6.0.21 per release line; upgrade API Control Plane to 4.5.0.58 or 4.6.0.22. See References for Traffic Manager and Universal Gateway boundaries.
  • Restrict network access to WSO2 management interfaces and authentication endpoints to known, trusted IP ranges. Internet-facing exposure of these endpoints significantly increases risk given the unauthenticated, network-reachable nature of this flaw.
  • Review and explicitly configure the allowed JWT signing algorithms in each product's security settings, rejecting any token whose algorithm header does not match the approved list, as a defense-in-depth measure beyond the patch.
  • Audit administrative accounts and active sessions on affected systems for signs of unauthorized access, and rotate credentials for any privileged accounts that may have been exposed prior to patching.

Key dates

Published (NVD)
August 6, 2026
Added to CISA KEV
September 24, 2026
Remediation deadline
September 27, 2026
Last updated
September 25, 2026

References

Frequently asked questions

Does CVE-2026-5430 affect my FedRAMP authorization?

If WSO2 Multiple Products runs inside your authorization boundary, yes. CVE-2026-5430 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 27, 2026, a date that has already passed. For a FedRAMP-authorized service, an unpatched KEV in the boundary is a finding. An overdue one is visible to your assessor and sponsoring agency now. Your path forward is remediation or formal documentation of the mitigation and the delay.

How does Knox help me handle CVE-2026-5430?

Knox does not patch your software. Remediating WSO2 Multiple Products is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2026-5430, that means exposure surfaces during continuous monitoring rather than waiting for an assessor to flag it at scheduled review time.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-5430's remediation deadline of September 27, 2026 has passed. What happens now?

An unremediated CVE-2026-5430 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.