CVE-2025-14561
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
06/08/2026
Última modificación:
07/08/2026
Descripción
*** Pendiente de traducción *** In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants.<br />
<br />
The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is only realized in multi-tenant deployments.
Impacto
Puntuación base 3.x
9.00
Gravedad 3.x
CRÍTICA



