CVE-2025-14561

CRITICAL CVSS 3.1: 9.0 EPSS 0.39%
Updated Aug 07, 2026
In
Parameter Value
CVSS 9.0 (CRITICAL)
Type CWE-284 (Improper Access Control)
Vendor In
Public PoC No

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment.

This impact is only realized in multi-tenant deployments.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v3.1