A vulnerability labeled as critical has been found in Microsoft Azure API Management. The impacted element is an unknown function. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-35425. It is possible to launch the attack remotely. No exploit is available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.