Multi-Tenant Deployment Flaw in WSO2 Publisher APIs
CVE-2025-14561
9CRITICAL
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2025-14561?
In multi-tenant environments, a vulnerability in WSO2 Publisher REST APIs compromises tenant isolation. This issue allows a user with sufficient privileges in one tenant to invoke these APIs, impacting the operations of other tenants. As a result, privileged users could manipulate API metadata or perform other publisher-related actions across different tenant environments, leading to potential data exposure or integrity issues.
Affected Version(s)
WSO2 API Control Plane 4.5.0 < 4.5.0.42
WSO2 API Control Plane 4.6.0 < 4.6.0.7
WSO2 API Manager 4.1.0 < 4.1.0.242
