Answer in brief
CVE-2025-14561 records a Critical severity (CVSS 9.0) vulnerability in Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon API Management Implementation (generic), WSO2/WSO2 Carbon API Manager Rest API Utility (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon API Management Implementation (generic), WSO2/WSO2 Carbon API Manager Rest API Utility (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.42 || >=4.6.0 <4.6.0.7 | 4.5.0.42, 4.6.0.7 |
| WSO2/WSO2 API Managergeneric | >=4.1.0 <4.1.0.242 || >=4.2.0 <4.2.0.182 || >=4.3.0 <4.3.0.93 || >=4.4.0 <4.4.0.57 || >=4.5.0 <4.5.0.41 || >=4.6.0 <4.6.0.6 | 4.1.0.242, 4.2.0.182, 4.3.0.93, 4.4.0.57, 4.5.0.41, 4.6.0.6 |
| WSO2/WSO2 Carbon API Management Implementationgeneric | >=9.20.74 <9.20.74.388 || >=9.28.116 <9.28.116.395 || >=9.29.120 <9.29.120.213 || >=9.30.67 <9.30.67.135 || >=9.31.86 <9.31.86.108 || >=9.32.147 <9.32.147.5 | 9.20.74.388, 9.28.116.395, 9.29.120.213, 9.30.67.135, 9.31.86.108, 9.32.147.5 |
| WSO2/WSO2 Carbon API Manager Rest API Utilitygeneric | >=9.20.74 <9.20.74.388 || >=9.28.116 <9.28.116.395 || >=9.29.120 <9.29.120.213 || >=9.30.67 <9.30.67.135 || >=9.31.86 <9.31.86.108 || >=9.32.147 <9.32.147.5 | 9.20.74.388, 9.28.116.395, 9.29.120.213, 9.30.67.135, 9.31.86.108, 9.32.147.5 |
| WSO2/WSO2 Traffic Managergeneric | >=4.5.0 <4.5.0.40 || >=4.6.0 <4.6.0.6 | 4.5.0.40, 4.6.0.6 |
| WSO2/WSO2 Universal Gatewaygeneric | >=4.5.0 <4.5.0.40 || >=4.6.0 <4.6.0.6 | 4.5.0.40, 4.6.0.6 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-14561 records a Critical severity (CVSS 9.0) vulnerability in Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations. The current sources do not mark it as known exploited. The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon API Management Implementation (generic), WSO2/WSO2 Carbon API Manager Rest API Utility (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WSO2/WSO2 API Control Plane (generic), WSO2/WSO2 API Manager (generic), WSO2/WSO2 Carbon API Management Implementation (generic), WSO2/WSO2 Carbon API Manager Rest API Utility (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WSO2/WSO2 API Control Planegeneric | >=4.5.0 <4.5.0.42 || >=4.6.0 <4.6.0.7 | 4.5.0.42, 4.6.0.7 |
| WSO2/WSO2 API Managergeneric | >=4.1.0 <4.1.0.242 || >=4.2.0 <4.2.0.182 || >=4.3.0 <4.3.0.93 || >=4.4.0 <4.4.0.57 || >=4.5.0 <4.5.0.41 || >=4.6.0 <4.6.0.6 | 4.1.0.242, 4.2.0.182, 4.3.0.93, 4.4.0.57, 4.5.0.41, 4.6.0.6 |
| WSO2/WSO2 Carbon API Management Implementationgeneric | >=9.20.74 <9.20.74.388 || >=9.28.116 <9.28.116.395 || >=9.29.120 <9.29.120.213 || >=9.30.67 <9.30.67.135 || >=9.31.86 <9.31.86.108 || >=9.32.147 <9.32.147.5 | 9.20.74.388, 9.28.116.395, 9.29.120.213, 9.30.67.135, 9.31.86.108, 9.32.147.5 |
| WSO2/WSO2 Carbon API Manager Rest API Utilitygeneric | >=9.20.74 <9.20.74.388 || >=9.28.116 <9.28.116.395 || >=9.29.120 <9.29.120.213 || >=9.30.67 <9.30.67.135 || >=9.31.86 <9.31.86.108 || >=9.32.147 <9.32.147.5 | 9.20.74.388, 9.28.116.395, 9.29.120.213, 9.30.67.135, 9.31.86.108, 9.32.147.5 |
| WSO2/WSO2 Traffic Managergeneric | >=4.5.0 <4.5.0.40 || >=4.6.0 <4.6.0.6 | 4.5.0.40, 4.6.0.6 |
| WSO2/WSO2 Universal Gatewaygeneric | >=4.5.0 <4.5.0.40 || >=4.6.0 <4.6.0.6 | 4.5.0.40, 4.6.0.6 |
Published upstream
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Quoted source text, attributed separately from HOL analysis.