Threat intel / CVE tracker
CVE-2026-5430
Critical KEV · actively exploited PoC availableCVSS base score
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HThe JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Vendor
wso2
Product
api control plane
Affected
wso2 api control plane
Weakness
CWE-347 · Vulnerability
Published
Aug 6, 2026
Last modified
Aug 10, 2026
CVSS version
v3.1
Views
0
// References & exploits