CVE-2025-13767

MEDIUM

Mattermost 10.11.0-10.11.7, 10.12.0-10.12.3, 11.0.0-11.0.5, 11.1.0 - Incorrect Authorization in Jira Plugin

Title source: llm
STIX 2.1

Description

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
mattermost/mattermost 0 - 8.0.0-20251121122154-b57c297c6d7Go
mattermost/mattermost-server 10.11.0 - 10.11.8Go
mattermost/mattermost_server 10.11.0 - 10.11.8
Published Dec 24, 2025
Tracked Since Feb 18, 2026