WSO2: Vulnerability in open-source API manager used by Telstra & Vodafone under active exploitation

WSO2: Vulnerability in open-source API manager used by Telstra & Vodafone under active exploitation

Critical WSO2 API Manager Vulnerability Exploited in the Wild

Unidentified threat actors have begun exploiting CVE-2026-5430, a critical authentication bypass vulnerability in WSO2 API Manager, nearly five months after a patch was released. The flaw, tracked with a CVSS score of 10 (downgraded to 9.8 in single-tenant deployments), allows attackers to forge JWT tokens with administrator privileges, granting full access to backend APIs, credentials, and sensitive data in transit.

Security firm watchTowr Intel detected exploitation attempts on September 13, with attackers leveraging the vulnerability to intercept API requests and move laterally within compromised systems. The flaw affects WSO2 API Manager versions 4.1.0 through 4.6.0, as well as the API Control Plane, Traffic Manager, and Universal Gateway.

Despite WSO2’s initial patch in April and a public advisory in May, the severity of the issue was initially downplayed in the patch notes, which labeled it as an "improvement in exception handling." The vulnerability’s high impact stems from its ability to expose consumer keys, secrets, and internal service interactions, effectively turning the platform into a "Lateral Movement-as-a-Service" tool for attackers.

While WSO2 may not be widely recognized, its enterprise customer base spanning banking, government, telecom, and logistics across 90+ countries makes it a high-value target. Researchers noted that the attackers initially targeted the wrong product but successfully exploited the real one when tested, raising concerns about potential undetected breaches in live environments.

Source: https://www.cyberdaily.au/security/14192-vulnerability-in-open-source-api-manager-used-by-telstra-vodafone-under-active-exploitation

WSO2 cybersecurity rating report: https://www.rankiteo.com/company/wso2

"id": "WSO1789532611",
"linkid": "wso2",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Banking',
                                     'Government',
                                     'Telecom',
                                     'Logistics'],
                        'location': '90+ countries',
                        'name': 'WSO2 API Manager Customers',
                        'type': 'Enterprise'}],
 'attack_vector': 'Exploitation of unpatched vulnerability (CVE-2026-5430)',
 'data_breach': {'personally_identifiable_information': 'Possible',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Credentials',
                                              'Sensitive data in transit',
                                              'Internal service interactions']},
 'date_detected': '2023-09-13',
 'date_publicly_disclosed': '2023-05-01',
 'description': 'Unidentified threat actors have begun exploiting '
                'CVE-2026-5430, a critical authentication bypass vulnerability '
                'in WSO2 API Manager, nearly five months after a patch was '
                'released. The flaw allows attackers to forge JWT tokens with '
                'administrator privileges, granting full access to backend '
                'APIs, credentials, and sensitive data in transit. Attackers '
                'leveraged the vulnerability to intercept API requests and '
                'move laterally within compromised systems.',
 'impact': {'data_compromised': 'Consumer keys, secrets, internal service '
                                'interactions, sensitive data in transit',
            'identity_theft_risk': 'High (exposure of personally identifiable '
                                   'information possible)',
            'operational_impact': 'Lateral movement within compromised '
                                  'systems, full access to backend APIs',
            'systems_affected': 'WSO2 API Manager (versions 4.1.0 through '
                                '4.6.0), API Control Plane, Traffic Manager, '
                                'Universal Gateway'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Immediate patch deployment, '
                                                  'enhanced monitoring for JWT '
                                                  'token forgery, and improved '
                                                  'vulnerability disclosure '
                                                  'practices.',
                            'root_causes': 'Insufficient patch prioritization, '
                                           'delayed public disclosure of '
                                           'severity, and mislabeling of the '
                                           "vulnerability as an 'improvement "
                                           "in exception handling'."},
 'recommendations': 'Apply the patch released in April 2023, monitor for '
                    'unauthorized JWT token generation, and review API access '
                    'logs for signs of lateral movement.',
 'references': [{'source': 'watchTowr Intel'}, {'source': 'WSO2 Advisory'}],
 'response': {'remediation_measures': 'Patch application (released in April '
                                      '2023)',
              'third_party_assistance': 'watchTowr Intel'},
 'threat_actor': 'Unidentified threat actors',
 'title': 'Critical WSO2 API Manager Vulnerability Exploited in the Wild',
 'type': 'Authentication Bypass',
 'vulnerability_exploited': 'CVE-2026-5430'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.