cbcvebase.
CVE-2025-12419
published 2025-11-27

CVE-2025-12419: Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID…

PriorityP266critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.32%
23.8th percentile
Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system with one of them never having logged into Mattermost.

Affected

13 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.11.0 < 10.11.510.11.5
github.commattermost_mattermost-server>= 10.12.0 < 10.12.210.12.2
github.commattermost_mattermost-server>= 10.5.0 < 10.5.1310.5.13
github.commattermost_mattermost-server>= 11.0.0 < 11.0.411.0.4
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20251028000919-d3ed703dc8338.0.0-20251028000919-d3ed703dc833
mattermostmattermost10.11.0 – 10.11.4
mattermostmattermost10.12.0 – 10.12.1
mattermostmattermost10.5.0 – 10.5.12
mattermostmattermost11.0.0 – 11.0.3
mattermostmattermost_server>= 10.11.0 < 10.11.510.11.5
mattermostmattermost_server>= 10.12.0 < 10.12.210.12.2
mattermostmattermost_server>= 10.5.0 < 10.5.1310.5.13
mattermostmattermost_server>= 11.0.0 < 11.0.411.0.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.