---
id: CVE-2025-14561
title: >-
  In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant
  isolation correctly
summary: >-
  In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant
  isolation correctly. This allows a user in one tenant, possessing sufficient
  privileges to invoke these APIs, to perform operations that impact other
  tenants.


  T…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L'
cwe:
  - CWE-284
published: '2026-08-06'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T11:10:00.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14561'
references:
  - url: >-
      https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4918/
    label: ed10eef1-636d-4fbe-9993-6890dfa878f8
tags:
  - nvd
ingestedAt: '2026-09-29T11:32:41.218Z'
---

## Overview

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.

The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
