Wso2 · Wso2 Api Control Plane · CVE-2026-5430
**Name of the Vulnerable Software and Affected Versions**
WSO2 API Manager (affected versions not specified)
**Description**
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JSON Web Token (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—using an unsupported algorithm. Because the system incorrectly validates these tokens, it can lead to unauthorized access, including the potential compromise of administrative accounts and full account takeover.
**Recommendations**
Update WSO2 API Manager to the latest patched version.