CISA's WSO2 Catalog Entry Names the Wrong Vulnerability
Security / analysis
CISA's WSO2 Catalog Entry Names the Wrong Vulnerability
The agency's Sept. 24 addition of CVE-2026-5430 borrows language from a different, four-year-old WSO2 flaw, even as watchTowr reports live attacks forging admin tokens through the real one.
CISA's own description of the WSO2 flaw under active attack this month does not match the vulnerability that WSO2, the National Vulnerability Database and the researchers tracking exploitation all describe. The agency added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on Sept. 24, giving federal civilian agencies until today, Sept. 27, to patch.
CISA's catalog entry calls the flaw the "WSO2 Multiple Products Path Traversal Vulnerability" and describes it as a bug that "could allow for unrestricted file upload and lead to remote code execution." WSO2's own advisory, and NVD's published description, describe something else entirely: a JSON Web Token authentication bypass that lets an attacker forge an administrator credential.
What the catalog's own metadata gives away
The mismatch shows up in the catalog entry's own tagging. CISA classifies CVE-2026-5430 under CWE-347, the weakness category for improper verification of a cryptographic signature, which is the correct category for a token-forgery bug and the wrong one for path traversal. Path traversal carries its own, different code, CWE-22, and CISA used exactly that tag on a different WSO2 flaw, CVE-2022-29464, added to the same catalog on Apr. 25, 2022, and described then as letting "multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution." The 2026 entry's wording tracks that older sentence closely. Whether the text was copied from the 2022 entry or is a templating error affecting only this vendor is not addressed anywhere in CISA's public catalog.
What the bug actually does, according to WSO2 and NVD
WSO2's advisory and NVD's description agree with each other, if not with CISA's summary. The JWT validation logic in API Manager, API Control Plane, Traffic Manager and Universal Gateway accepts a token signed with an algorithm the deployment does not support, instead of rejecting it, WSO2's advisory says. An attacker can craft a token naming an unsupported algorithm and have it validated anyway, reaching full administrative access, NVD's own description confirms.
NVD scores the flaw 10.0 in multi-tenant deployments and 9.8 in single-tenant ones, under a vector requiring no privileges and no user interaction. It affects API Manager 4.1.0 through 4.6.0, API Control Plane 4.5.0 and 4.6.0, Traffic Manager 4.5.0 and 4.6.0, and Universal Gateway 4.5.0 and 4.6.0, all patched in a WSO2 advisory dated May 3, 2026 and credited to the Hacktron Team. Subscription customers patch by applying a specific update level per product line, for example Update 21 on API Manager 4.6.0 and Update 57 on API Manager 4.5.0; open-source users pull the fix from WSO2's own GitHub pull requests instead, according to the advisory.
| CVE | Real vulnerability type | CWE tag | Added to KEV |
|---|---|---|---|
| CVE-2026-5430 | JWT signature bypass | CWE-347 | Sept. 24, 2026 |
| CVE-2022-29464 | Unrestricted file upload | CWE-22 | Apr. 25, 2022 |
Attacks began four months after the patch
watchTowr's honeypots began capturing forged administrator tokens targeting the flaw on Sept. 13, more than four months after WSO2 shipped a fix, Yordan Ganchev, the firm's principal threat intelligence specialist, said. "The forged token yields access to every API backend endpoint and its credentials, consumer keys and secrets for every registered application," Ganchev said. The affected gateway service is "by definition made to intercept API requests on their way to internal systems, which provides a great opportunity to tap and steal sensitive data in transit," he said.
WSO2 counts nearly 1,000 enterprise customers across banking, government, telecommunications and logistics, SecurityWeek reported, though neither WSO2 nor watchTowr has said how many internet-exposed instances remain unpatched.
A neighboring entry, correctly labeled
CISA added a second flaw the same day, CVE-2026-71362, an incorrect-authorization bug in Adobe Commerce and Magento that lets an attacker switch a customer session to another account without logging in, and its catalog description matches that behavior. Sansec, a Dutch e-commerce security firm, said it detected and blocked exploitation attempts in August; Previdian's telemetry separately logged an Australian IP address attempting exploitation on Sept. 10. Adobe has not confirmed exploitation in its own advisory. That entry's accuracy is what makes the WSO2 entry's mismatch look like an isolated error rather than a routine practice.
Why the mislabeling probably doesn't change the remediation
The error has no apparent effect on what agencies are actually told to do. CISA's requiredAction field directs agencies to apply WSO2's fix under Binding Operational Directive 26-04 regardless of which description is accurate, and the Sept. 27 deadline stands either way. The practical risk falls on anyone who reads only the catalog's vulnerability name, a path-traversal label, and mistakes a routine file-upload bug for what WSO2 and NVD actually describe: an unauthenticated route to administrator access across a company's entire API gateway, the kind of internet-facing infrastructure bug this site has tracked through CISA's other September catalog additions.
If CISA corrects the entry's name and description to match its own CWE-347 tag, that would support the editing-error explanation over a broader mislabeling practice. As of Sept. 27, the entry remains uncorrected, the same day CISA's separate MikroTik router addition set its own deadline under the identical directive.
Sources
- CISA Known Exploited Vulnerabilities Catalog (data feed), CISA
- Security Advisory WSO2-2026-5328, WSO2
- CVE-2026-5430 Detail, National Vulnerability Database
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens, The Hacker News
- Enterprises Warned of Attacks Exploiting WSO2 Vulnerability, SecurityWeek
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV, The Hacker News
Sources
More in Security
- 01Siemens' Edge Platform Still Carried a Keycloak Bug Fixed in AugustCISA published the advisory on Sept. 22, more than a month after Red Hat shipped the upstream fix, because four Siemens Industrial Edge Management products bundle the identity server.
- 02LuaRocks Patches a Bytecode Flaw Attackers Used for Six WeeksAn independent researcher's writeup, published a day after the fix, names the LuaJIT instruction that let a crafted package listing read and write server memory.
- 03Graphalgo Malware Reaches Terraform Providers for the First TimeTwo fake Terraform providers and two Go modules polled an Ethereum contract every 3 seconds as a backup channel, security firm Aikido said, describing the campaign's first use of HashiCorp's registry.
- 04Microsoft's SharePoint 'Spoofing' Bug Is Really an RCE FlawCVE-2026-65660 sat rated 6.5 for weeks until a Viettel researcher showed it grants remote code execution, and CISA added it to its exploited-vulnerabilities catalog Sept. 25 after attackers began installing webshells.