Impact
The vulnerability occurs when publisher REST APIs in WSO2 multi‑tenant products do not enforce proper tenant isolation. A privileged user in one tenant can invoke these APIs and modify or expose API metadata that belongs to another tenant, thereby compromising data integrity and confidentiality across tenants. This flaw enables cross‑tenant manipulation of API configuration, potentially affecting the operation and security posture of other tenants.
Affected Systems
WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon API Management Implementation, WSO2 Carbon API Manager Rest API Utility, WSO2 Traffic Manager, and WSO2 Universal Gateway are affected. No specific version numbers are provided in the advisory, so all versions of these products may be vulnerable.
Risk and Exploitability
The issue scores a CVSS of 9.0, indicating a critical severity. No EPSS score is available, and it is not listed in CISA's KEV catalog, suggesting no public proof‑of‑concept exploit has yet been reported. Exploitation requires a user with sufficient privileges in the publisher REST interface and a multi‑tenant deployment; the attacker must be able to send authenticated API requests, implying an internal or compromised account. Once the attack vector is available, the attacker can impact other tenants by altering API metadata.
OpenCVE Enrichment