Executive brief
WSO2 products are widely used for identity and access management in enterprises. A path traversal flaw allows attackers to read sensitive files and configuration data from affected systems. CISA has confirmed active exploitation of this vulnerability, making it a priority for immediate patching to prevent data breaches and system compromise.
Technical details
CVE-2026-5430 is a path traversal vulnerability in WSO2 Multiple Products that allows attackers to access files and directories outside the intended root directory through improper input validation. The vulnerability is remotely exploitable and does not require authentication. Attackers can leverage this flaw to read sensitive configuration files, credentials, and application data. CISA has added this vulnerability to the Known Exploited Vulnerabilities Catalog based on confirmed evidence of active exploitation in the wild. Federal agencies and all organizations are urged to prioritize patching this vulnerability on publicly exposed assets.
Affected products
- WSO2 Multiple Products
Timeline
- 2026-09-24: kev added: CISA adds CVE-2026-5430 to Known Exploited Vulnerabilities Catalog