Description
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.
The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4918/#solution
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments. | |
| Title | Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations | |
| First Time appeared |
Wso2
Wso2 wso2 Api Control Plane Wso2 wso2 Api Manager Wso2 wso2 Carbon Api Management Implementation Wso2 wso2 Carbon Api Manager Rest Api Utility Wso2 wso2 Traffic Manager Wso2 wso2 Universal Gateway |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_carbon_api_manager_rest_api_utility:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2 Api Control Plane Wso2 wso2 Api Manager Wso2 wso2 Carbon Api Management Implementation Wso2 wso2 Carbon Api Manager Rest Api Utility Wso2 wso2 Traffic Manager Wso2 wso2 Universal Gateway |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-08-06T17:32:07.810Z
Reserved: 2025-12-12T07:13:05.500Z
Link: CVE-2025-14561
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T03:15:03Z
Weaknesses