CVE-2025-14561

CRITICALCVSS 9/10EPSS 0.39%

Last modified

CVE-2025-14561 is a critical-severity vulnerability rated 9/10 on the CVSS scale. In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. EPSS estimates a 0.39% chance of exploitation in the next 30 days.

Description

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.

Metrics

CVSS 3.1
9/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

EPSS Probability
0.39%

31.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
WSO2WSO2 API Manager>= 4.1.0, < 4.1.0.242; >= 4.2.0, < 4.2.0.182; >= 4.3.0, < 4.3.0.93; >= 4.4.0, < 4.4.0.57; >= 4.5.0, < 4.5.0.41; >= 4.6.0, < 4.6.0.6
WSO2WSO2 API Control Plane>= 4.5.0, < 4.5.0.42; >= 4.6.0, < 4.6.0.7
WSO2WSO2 Traffic Manager>= 4.5.0, < 4.5.0.40; >= 4.6.0, < 4.6.0.6
WSO2WSO2 Universal Gateway>= 4.5.0, < 4.5.0.40; >= 4.6.0, < 4.6.0.6
WSO2WSO2 Carbon API Management Implementation>= 9.20.74, < 9.20.74.388; >= 9.28.116, < 9.28.116.395; >= 9.29.120, < 9.29.120.213; >= 9.30.67, < 9.30.67.135; >= 9.31.86, < 9.31.86.108; >= 9.32.147, < 9.32.147.5
WSO2WSO2 Carbon API Manager Rest API Utility>= 9.20.74, < 9.20.74.388; >= 9.28.116, < 9.28.116.395; >= 9.29.120, < 9.29.120.213; >= 9.30.67, < 9.30.67.135; >= 9.31.86, < 9.31.86.108; >= 9.32.147, < 9.32.147.5

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2025-14561?
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
How severe is CVE-2025-14561?
CVE-2025-14561 has a CVSS score of 9/10 (CRITICAL severity). The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2025-14561?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-14561?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST