← Global Threat Landscape

CVE-2026-5430

CWE-347

High

80.9

RPS

Description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

Source: NVD

Signals

CVSS
10.0
Critical · v3.1
EPSS
0.58%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Sept 2026
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-347
Published
6 Aug 2026
Last modified 25 Sept 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2026-5430

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2026-5430 · RPS 80.9 · DevSecure Intelligence