PT-2026-53824 · Wso2 · Wso2 Api Control Plane+8
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WSO2 API Manager (affected versions not specified)
Description
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JSON Web Token (JWT)—a compact, URL-safe means of representing claims to be transferred between two parties—using an unsupported algorithm. Because the system incorrectly validates these tokens, it can lead to unauthorized access, including the potential compromise of administrative accounts and full account takeover.
Recommendations
Update WSO2 API Manager to the latest patched version.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Api Control Plane
Wso2 Api Manager
Wso2 Carbon Api Manager Rest Api Utility
Wso2 Traffic Manager
Wso2 Universal Gateway
Api Control Plane
Aimanager
Traffic Manager
Universal Gateway