CVE-2025-13870

LOW

Mattermost 10.5.0-10.5.12 and 10.11.0-10.11.4 - Authenticated Missing Permission Validation in Boards

Title source: llm
STIX 2.1

Description

Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to

References (1)

Core 1
Core References

Scores

CVSS v3 3.1
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
mattermost/mattermost 0 - 8.0.0-20250905150616-ba86dfc5876bGo
mattermost/mattermost 10.11.0 - 10.11.5Go
mattermost/mattermost_server 10.5.0 - 10.5.13
Published Dec 02, 2025
Tracked Since Feb 18, 2026