Vulnerability Intelligence Report
Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations
CVE-2025-14561
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
No Active Exploit Signals
CVSS Base Score
9.0
CRITICAL
Exploitability:2.3
Impact Score:6.0
EPSS Probability:0.39%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-284 ↗CWE-284: Improper Access Control
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| WSO2 | WSO2 API Manager | 4.1.0 < 4.1.0.242 (affected), 4.2.0 < 4.2.0.182 (affected), 4.3.0 < 4.3.0.93 (affected), 4.4.0 < 4.4.0.57 (affected), 4.5.0 < 4.5.0.41 (affected), 4.6.0 < 4.6.0.6 (affected) |
| WSO2 | WSO2 API Control Plane | 4.5.0 < 4.5.0.42 (affected), 4.6.0 < 4.6.0.7 (affected) |
| WSO2 | WSO2 Traffic Manager | 4.5.0 < 4.5.0.40 (affected), 4.6.0 < 4.6.0.6 (affected) |
| WSO2 | WSO2 Universal Gateway | 4.5.0 < 4.5.0.40 (affected), 4.6.0 < 4.6.0.6 (affected) |
| WSO2 | WSO2 Carbon API Management Implementation | 9.20.74 < 9.20.74.388 (affected), 9.28.116 < 9.28.116.395 (affected), 9.29.120 < 9.29.120.213 (affected), 9.30.67 < 9.30.67.135 (affected), 9.31.86 < 9.31.86.108 (affected), 9.32.147 < 9.32.147.5 (affected), 9.32.160 <= * (unaffected) |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | 9.20.74 < 9.20.74.388 (affected), 9.28.116 < 9.28.116.395 (affected), 9.29.120 < 9.29.120.213 (affected), 9.30.67 < 9.30.67.135 (affected), 9.31.86 < 9.31.86.108 (affected), 9.32.147 < 9.32.147.5 (affected), 9.32.160 <= * (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.386%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | WSO2 LLC · Vendor · USA |
| Reserved | 2025-12-12T07:13:05 |
| Published | 2026-08-06T17:32:07 |
| Last Updated | 2026-08-07T17:48:30 |
Community Chatter & Buzz