What is CVE-2025-14561?
CVE-2025-14561 is a vulnerability in multi-tenant deployments where Publisher REST APIs fail to properly enforce tenant isolation. This allows a privileged user in one tenant to perform operations impacting other tenants, provided they have sufficient permissions to invoke the APIs. Immediate application of relevant patches is recommended to mitigate the risk.
Azərbaycanca: CVE-2025-14561 çox-icarəli (multi-tenant) mühitlərdə Publisher REST API-lərinin icarəçi izolyasiyasını düzgün tətbiq etməməsi zəifliyidir. Bu, bir icarəçidəki imtiyazlı istifadəçiyə, kifayət qədər icazəyə sahib olduğu təqdirdə, digər icarəçilərə təsir edən əməliyyatlar aparmağa imkan verir. Təhlükəsizliyi təmin etmək üçün dərhal müvafiq yamaqları tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Who can exploit CVE-2025-14561?
A privileged user in one tenant of a multi-tenant deployment can exploit this vulnerability, provided they have sufficient permissions to invoke the Publisher REST APIs.
How to mitigate the risk of CVE-2025-14561?
To mitigate the risk, immediate application of the relevant patches is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.