Multi-Tenant Deployment Flaw in WSO2 Publisher APIs
CVE-2025-14561

9CRITICAL

What is CVE-2025-14561?

In multi-tenant environments, a vulnerability in WSO2 Publisher REST APIs compromises tenant isolation. This issue allows a user with sufficient privileges in one tenant to invoke these APIs, impacting the operations of other tenants. As a result, privileged users could manipulate API metadata or perform other publisher-related actions across different tenant environments, leading to potential data exposure or integrity issues.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.42

WSO2 API Control Plane 4.6.0 < 4.6.0.7

WSO2 API Manager 4.1.0 < 4.1.0.242

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.