CVE-2025-14561: Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.
The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WSO2 products (Publisher REST APIs affected)to a version that resolves this vulnerability.Patch WSO2-2025-4918 - Configuration
Apply the solution for WSO2-2025-4918 to ensure Publisher REST APIs correctly enforce tenant isolation in multi-tenant deployments.
WSO2 multi-tenant deployments tenant isolation enforcement for Publisher REST APIs = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14561?
CVE-2025-14561 has a severity rating of critical with a CVSS score of 9.
What are the potential impacts of CVE-2025-14561?
CVE-2025-14561 may allow privileged users to perform unauthorized operations across different tenants.
How do I fix CVE-2025-14561?
To mitigate CVE-2025-14561, ensure proper enforcement of tenant isolation in the Publisher REST APIs during configuration.
Which products are affected by CVE-2025-14561?
CVE-2025-14561 affects multiple WSO2 products that utilize Publisher REST APIs in multi-tenant environments.
How can I detect exploitation of CVE-2025-14561?
You can detect exploitation of CVE-2025-14561 by monitoring API access logs for unauthorized operations conducted by users across tenants.