A flaw in how WSO2’s API gateway and control plane products validate JWT signing algorithms lets an attacker forge a token and walk in as an administrator, no login required.