Impact
The flaw is a JWT algorithm mismatch vulnerability (CWE-347) where the authentication mechanism accepts tokens signed with algorithms that are not explicitly configured or supported. An attacker can craft a JWT using an unsupported algorithm and the system will incorrectly validate it, allowing unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. This vulnerability can result in loss of confidentiality, integrity, and availability within the affected WSO2 deployments.
Affected Systems
Any deployed instance of WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon API Manager Rest API Utility, WSO2 Traffic Manager, or WSO2 Universal Gateway that has not applied the official patch is vulnerable. The specific versions are not listed in the advisory, so any version prior to the fix is considered at risk.
Risk and Exploitability
The vulnerability is exploitable remotely by sending a crafted JWT to any endpoint that performs authentication. The CVSS score is listed as 10, with a 9.8 score for single‑tenant deployments, indicating very high severity. The EPSS score of 0.0058 suggests a very low but non‑zero exploitation probability. The vulnerability is listed in the CISA KEV catalog, indicating that documented exploitation may exist. The attacker’s ability to generate an unauthorized token and bypass authentication makes remediation a priority.
OpenCVE Enrichment