Intel

AIKIDO-2026-196810

org.wso2.carbon.apimgt.rest.api.util is vulnerable to Authentication Bypass

Authentication BypassCVE-2026-5430 Published 4 days ago

100

Critical Risk

This Affects:

JAVAorg.wso2.carbon.apimgt.rest.api.util
9.20.74 - 9.20.74.400
Fixed in 9.20.74.401
9.28.116 - 9.28.116.416
Fixed in 9.28.116.417
9.29.120 - 9.29.120.235
Fixed in 9.29.120.236
9.30.67 - 9.30.67.166
Fixed in 9.30.67.167
9.31.86 - 9.31.86.157
Fixed in 9.31.86.158
9.32.147 - 9.32.147.58
Fixed in 9.32.147.59
Are you affected? Scan for Free

TL;DR

JWT authentication can accept a token signed with an unsupported algorithm, allowing unauthorized access and possible account takeover.

Who does this affect?

You are affected if your deployment uses JWT authentication and accepts tokens signed with unsupported algorithms.

Background info

org.wso2.carbon.apimgt.rest.api.util is vulnerable to Authentication Bypass in versions 9.20.74 - 9.20.74.400, 9.28.116 - 9.28.116.416, 9.29.120 - 9.29.120.235, 9.30.67 - 9.30.67.166, 9.31.86 - 9.31.86.157 and 9.32.147 - 9.32.147.58.

How to fix this

Upgrade the org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform