On Sept. 24, CISA added WSO2 API Manager’s JWT bypass—CVSS 10.0 in multi-tenant deployments—to its exploited-vulnerabilities catalog, setting a Sept. 27 federal deadline. A patch has been available since April; watchTowr first captured forged admin tokens Sept. 13.
WSO2’s validator accepts JWTs signed with an unsupported algorithm rather than rejecting them, allowing an attacker without credentials to obtain administrator status and full API-management scope. watchTowr researcher Yordan Ganchev said the activity appeared aimed at enumerating API catalogs and extracting backend credentials, consumer keys and application secrets. No threat actor has been publicly linked to the exploitation.
Affected software includes WSO2 API Manager versions 4.1.0 through 4.6.0, as well as the API Control Plane, Traffic Manager and Universal Gateway components. WSO2 advisory WSO2-2026-5328 was published May 3, 2026. Community-edition fixes are available through GitHub pull requests; supported deployments’ update levels are documented in the advisory. Recommended measures include applying patches, restricting network access to management and admin interfaces, and checking logs for accepted JWTs whose header algorithm differs from the configured signing algorithm.
