9
CVE-2025-14561
- EPSS 0.39%
- Veröffentlicht 06.08.2026 22:16:41
- Zuletzt bearbeitet 07.08.2026 18:17:06
- CVE-Watchlists
- Unerledigt
Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWSO2
≫
Produkt
WSO2 API Manager
Default Statusunaffected
Version
4.1.0
Version <
4.1.0.242
Status
affected
Version
4.2.0
Version <
4.2.0.182
Status
affected
Version
4.3.0
Version <
4.3.0.93
Status
affected
Version
4.4.0
Version <
4.4.0.57
Status
affected
Version
4.5.0
Version <
4.5.0.41
Status
affected
Version
4.6.0
Version <
4.6.0.6
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 API Control Plane
Default Statusunaffected
Version
4.5.0
Version <
4.5.0.42
Status
affected
Version
4.6.0
Version <
4.6.0.7
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 Traffic Manager
Default Statusunaffected
Version
4.5.0
Version <
4.5.0.40
Status
affected
Version
4.6.0
Version <
4.6.0.6
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 Universal Gateway
Default Statusunaffected
Version
4.5.0
Version <
4.5.0.40
Status
affected
Version
4.6.0
Version <
4.6.0.6
Status
affected
HerstellerWSO2
≫
Produkt
WSO2 Carbon API Management Implementation
Default Statusunknown
Version
9.20.74
Version <
9.20.74.388
Status
affected
Version
9.28.116
Version <
9.28.116.395
Status
affected
Version
9.29.120
Version <
9.29.120.213
Status
affected
Version
9.30.67
Version <
9.30.67.135
Status
affected
Version
9.31.86
Version <
9.31.86.108
Status
affected
Version
9.32.147
Version <
9.32.147.5
Status
affected
Version <=
*
Version
9.32.160
Status
unaffected
HerstellerWSO2
≫
Produkt
WSO2 Carbon API Manager Rest API Utility
Default Statusunknown
Version
9.20.74
Version <
9.20.74.388
Status
affected
Version
9.28.116
Version <
9.28.116.395
Status
affected
Version
9.29.120
Version <
9.29.120.213
Status
affected
Version
9.30.67
Version <
9.30.67.135
Status
affected
Version
9.31.86
Version <
9.31.86.108
Status
affected
Version
9.32.147
Version <
9.32.147.5
Status
affected
Version <=
*
Version
9.32.160
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.314 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ed10eef1-636d-4fbe-9993-6890dfa878f8 | 9 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4918/