Skip to finding
important · RCE — WSO2

WSO2 confirms a JWT authentication bypass, while CISA describes the same CVE as an exploited upload-to-RCE flaw.

Affects

WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway, Java-based API-management and gateway services.

WSO2’s account says an unsupported signing algorithm can yield administrative account takeover. CISA’s account instead names path traversal, unrestricted upload and remote code execution.

Detail and 2 sources

We do not know whether the CVE conflates two vulnerabilities or how the asserted upload path relates to the JWT flaw.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 25, 2026