Description
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.

The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Published: 2026-08-06
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs when publisher REST APIs in WSO2 multi‑tenant products do not enforce proper tenant isolation. A privileged user in one tenant can invoke these APIs and modify or expose API metadata that belongs to another tenant, thereby compromising data integrity and confidentiality across tenants. This flaw enables cross‑tenant manipulation of API configuration, potentially affecting the operation and security posture of other tenants.

Affected Systems

WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon API Management Implementation, WSO2 Carbon API Manager Rest API Utility, WSO2 Traffic Manager, and WSO2 Universal Gateway are affected. No specific version numbers are provided in the advisory, so all versions of these products may be vulnerable.

Risk and Exploitability

The issue scores a CVSS of 9.0, indicating a critical severity. No EPSS score is available, and it is not listed in CISA's KEV catalog, suggesting no public proof‑of‑concept exploit has yet been reported. Exploitation requires a user with sufficient privileges in the publisher REST interface and a multi‑tenant deployment; the attacker must be able to send authenticated API requests, implying an internal or compromised account. Once the attack vector is available, the attacker can impact other tenants by altering API metadata.

Generated by OpenCVE AI on August 6, 2026 at 23:20 UTC.

Remediation

Vendor Solution

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4918/#solution


OpenCVE Recommended Actions

  • Apply the vendor‑provided fix by following the instructions at the WSO2 security advisory page.
  • Enforce the principle of least privilege on publisher users to limit their authority to only the tenant they belong to.
  • Enhance tenant validation on all REST API calls and implement monitoring for cross‑tenant activity to detect improper usage.

Generated by OpenCVE AI on August 6, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Title Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations
First Time appeared Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Wso2 wso2 Carbon Api Management Implementation
Wso2 wso2 Carbon Api Manager Rest Api Utility
Wso2 wso2 Traffic Manager
Wso2 wso2 Universal Gateway
Weaknesses CWE-284
CPEs cpe:2.3:a:wso2:wso2_api_control_plane:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_api_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_carbon_api_management_implementation:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_carbon_api_manager_rest_api_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:wso2:wso2_universal_gateway:*:*:*:*:*:*:*:*
Vendors & Products Wso2
Wso2 wso2 Api Control Plane
Wso2 wso2 Api Manager
Wso2 wso2 Carbon Api Management Implementation
Wso2 wso2 Carbon Api Manager Rest Api Utility
Wso2 wso2 Traffic Manager
Wso2 wso2 Universal Gateway
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Wso2 Wso2 Api Control Plane Wso2 Api Manager Wso2 Carbon Api Management Implementation Wso2 Carbon Api Manager Rest Api Utility Wso2 Traffic Manager Wso2 Universal Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: WSO2

Published:

Updated: 2026-08-06T17:32:07.810Z

Reserved: 2025-12-12T07:13:05.500Z

Link: CVE-2025-14561

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T03:15:03Z

Weaknesses