CVE-2025-14561
Last modified
CVE-2025-14561 is a critical-severity vulnerability rated 9/10 on the CVSS scale. In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WSO2 | WSO2 API Manager | >= 4.1.0, < 4.1.0.242; >= 4.2.0, < 4.2.0.182; >= 4.3.0, < 4.3.0.93; >= 4.4.0, < 4.4.0.57; >= 4.5.0, < 4.5.0.41; >= 4.6.0, < 4.6.0.6 |
| WSO2 | WSO2 API Control Plane | >= 4.5.0, < 4.5.0.42; >= 4.6.0, < 4.6.0.7 |
| WSO2 | WSO2 Traffic Manager | >= 4.5.0, < 4.5.0.40; >= 4.6.0, < 4.6.0.6 |
| WSO2 | WSO2 Universal Gateway | >= 4.5.0, < 4.5.0.40; >= 4.6.0, < 4.6.0.6 |
| WSO2 | WSO2 Carbon API Management Implementation | >= 9.20.74, < 9.20.74.388; >= 9.28.116, < 9.28.116.395; >= 9.29.120, < 9.29.120.213; >= 9.30.67, < 9.30.67.135; >= 9.31.86, < 9.31.86.108; >= 9.32.147, < 9.32.147.5 |
| WSO2 | WSO2 Carbon API Manager Rest API Utility | >= 9.20.74, < 9.20.74.388; >= 9.28.116, < 9.28.116.395; >= 9.29.120, < 9.29.120.213; >= 9.30.67, < 9.30.67.135; >= 9.31.86, < 9.31.86.108; >= 9.32.147, < 9.32.147.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2025-14561?
How severe is CVE-2025-14561?
How do I fix CVE-2025-14561?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-14556Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2025-14557Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2025-14558The rtsol(8) and rtsold(8) programs do not validate the doma…7.2
- CVE-2025-14559A flaw was found in the keycloak-services component of Keycl…6.5
- CVE-2025-1456The Royal Elementor Addons and Templates plugin for WordPres…5.4
- CVE-2025-14560GitLab has remediated an issue in GitLab CE/EE affecting all…5.4
- CVE-2025-14562GitLab has remediated an issue in GitLab CE/EE affecting all…3.1
- CVE-2025-14565A vulnerability was identified in kidaze CourseSelectionSyst…9.8
- CVE-2025-14566A security flaw has been discovered in kidaze CourseSelectio…9.8
- CVE-2025-14567A weakness has been identified in haxxorsid Stock-Management…7.5
- CVE-2025-14568A security vulnerability has been detected in haxxorsid Stoc…6.3
- CVE-2025-14569A vulnerability was detected in ggml-org whisper.cpp up to 1…5.3
Are you affected by CVE-2025-14561?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
