{"id":"CVE-2025-14561","title":"In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly","summary":"In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.\n\nT…","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L","cwe":["CWE-284"],"published":"2026-08-06","updated":"2026-09-29","sourceUpdated":"2026-09-29T11:10:00.150","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14561","references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4918/","label":"ed10eef1-636d-4fbe-9993-6890dfa878f8"}],"tags":["nvd"],"ingestedAt":"2026-09-29T11:32:41.218Z","slug":"CVE-2025-14561","body":"## Overview\n\nIn multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.\n\nThe vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":49.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}