CVE-2025-14561 PUBLISHED

Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations

Assigner: WSO2
Reserved: 12.12.2025 Published: 06.08.2026 Updated: 06.08.2026

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.

The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
CVSS Score: 9

Product Status

Vendor WSO2
Product WSO2 API Manager
Versions Default: unaffected
  • affected from 4.1.0 to 4.1.0.242 (excl.)
  • affected from 4.2.0 to 4.2.0.182 (excl.)
  • affected from 4.3.0 to 4.3.0.93 (excl.)
  • affected from 4.4.0 to 4.4.0.57 (excl.)
  • affected from 4.5.0 to 4.5.0.41 (excl.)
  • affected from 4.6.0 to 4.6.0.6 (excl.)
Vendor WSO2
Product WSO2 API Control Plane
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.42 (excl.)
  • affected from 4.6.0 to 4.6.0.7 (excl.)
Vendor WSO2
Product WSO2 Traffic Manager
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.40 (excl.)
  • affected from 4.6.0 to 4.6.0.6 (excl.)
Vendor WSO2
Product WSO2 Universal Gateway
Versions Default: unaffected
  • affected from 4.5.0 to 4.5.0.40 (excl.)
  • affected from 4.6.0 to 4.6.0.6 (excl.)
Vendor WSO2
Product WSO2 Carbon API Management Implementation
Versions Default: unknown
  • affected from 9.20.74 to 9.20.74.388 (excl.)
  • affected from 9.28.116 to 9.28.116.395 (excl.)
  • affected from 9.29.120 to 9.29.120.213 (excl.)
  • affected from 9.30.67 to 9.30.67.135 (excl.)
  • affected from 9.31.86 to 9.31.86.108 (excl.)
  • affected from 9.32.147 to 9.32.147.5 (excl.)
  • unaffected from 9.32.160 to * (incl.)
Vendor WSO2
Product WSO2 Carbon API Manager Rest API Utility
Versions Default: unknown
  • affected from 9.20.74 to 9.20.74.388 (excl.)
  • affected from 9.28.116 to 9.28.116.395 (excl.)
  • affected from 9.29.120 to 9.29.120.213 (excl.)
  • affected from 9.30.67 to 9.30.67.135 (excl.)
  • affected from 9.31.86 to 9.31.86.108 (excl.)
  • affected from 9.32.147 to 9.32.147.5 (excl.)
  • unaffected from 9.32.160 to * (incl.)

Solutions

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4918/#solution

References

Problem Types

  • CWE-284: Improper Access Control CWE

Impacts

  • CAPEC-18 CAPEC-18: Access Control