Skip to finding
important · WSO2 — privilege

Active exploitation turns an unsupported JWT algorithm into WSO2 administrative takeover.

Affects

WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway, enterprise API-management and gateway services.

A network peer can present a forged token to an affected JWT-authenticated API. Once the verifier accepts it, the peer can invoke protected operations, obtain application credentials, and take management-plane control.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 27, 2026