A vulnerability marked as critical has been reported in WSO2 API Manager API Control Plane Identity Server. This vulnerability affects unknown code of the component URL Parameter. Performing a manipulation of the argument URL results in injection.

This vulnerability is cataloged as CVE-2026-2445. It is possible to initiate the attack remotely. There is no exploit available.