AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2025-14561

CRITICAL · CVSS 9 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

In multi-tenant deployments, the Publisher REST APIs lack proper tenant isolation, enabling a privileged user from one tenant to execute operations that can affect other tenants, including exposing or modifying API metadata. This critical vulnerability poses significant risks to data integrity and confidentiality across tenant environments. Organizations utilizing multi-tenant architectures should prioritize immediate remediation to safeguard against potential cross-tenant data breaches.

CVE
CVE-2025-14561
Severity
CRITICAL
CVSS
9
EPSS
0.39%

Original NVD Description

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.