CVE-2025-14561
Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations
CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
| CWE | CWE-284 |
| Vendor | wso2 |
| Product | wso2 api manager |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for wso2 wso2 api manager
Be the first to know when new critical vulnerabilities affecting wso2 wso2 api manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
Affected Versions
WSO2 / WSO2 API Manager
4.1.0 < 4.1.0.242 4.2.0 < 4.2.0.182 4.3.0 < 4.3.0.93 4.4.0 < 4.4.0.57 4.5.0 < 4.5.0.41 4.6.0 < 4.6.0.6
WSO2 / WSO2 API Control Plane
4.5.0 < 4.5.0.42 4.6.0 < 4.6.0.7
WSO2 / WSO2 Traffic Manager
4.5.0 < 4.5.0.40 4.6.0 < 4.6.0.6
WSO2 / WSO2 Universal Gateway
4.5.0 < 4.5.0.40 4.6.0 < 4.6.0.6
WSO2 / WSO2 Carbon API Management Implementation
9.20.74 < 9.20.74.388 9.28.116 < 9.28.116.395 9.29.120 < 9.29.120.213 9.30.67 < 9.30.67.135 9.31.86 < 9.31.86.108 9.32.147 < 9.32.147.5
WSO2 / WSO2 Carbon API Manager Rest API Utility
9.20.74 < 9.20.74.388 9.28.116 < 9.28.116.395 9.29.120 < 9.29.120.213 9.30.67 < 9.30.67.135 9.31.86 < 9.31.86.108 9.32.147 < 9.32.147.5