Impact
The flaw is a JWT algorithm mismatch vulnerability (CWE‑347) where the authentication mechanism accepts tokens signed with algorithms that are not explicitly configured or supported. An attacker can craft a JWT using an unsupported algorithm and the system will incorrectly validate it, allowing unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. This vulnerability can result in loss of confidentiality, integrity, and availability within the affected WSO2 deployments.
Affected Systems
Any deployed instance of WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon API Manager Rest API Utility, WSO2 Traffic Manager, or WSO2 Universal Gateway that has not applied the official patch is vulnerable. The specific versions are not listed in the advisory, so any version prior to the fix is considered at risk.
Risk and Exploitability
The vulnerability is exploitable remotely by sending a crafted JWT to any endpoint that performs authentication. The CVSS score is listed as 10, with the description noting a score of 9.8 for single‑tenant deployments, indicating a very high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, meaning there are currently no documented exploitation campaigns but the risk remains high. The attacker’s ability to generate an unauthorized token and bypass authentication makes remediation a priority.
OpenCVE Enrichment