CVE-2025-6226

MEDIUM

Mattermost <10.5.7, <10.8.2, <10.7.4, <9.11.17 - Info Disclosure

Title source: llm
STIX 2.1

Description

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0022
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
mattermost/mattermost 0 - 8.0.0-20250520130510-fa40a8c5d47fGo
mattermost/mattermost-server 10.5.0 - 10.5.7Go
mattermost/mattermost_server 9.11.0 - 9.11.17
Published Jul 18, 2025
Tracked Since Feb 18, 2026