CVE-2025-12756
published 2025-12-01CVE-2025-12756: Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.16%
5.8th percentile
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost | 10.11.0 – 10.11.4 | — |
| github.com | mattermost_mattermost | >= 10.11.0+incompatible | — |
| github.com | mattermost_mattermost | 10.12.0 – 10.12.1 | — |
| github.com | mattermost_mattermost | >= 10.12.0+incompatible | — |
| github.com | mattermost_mattermost | 10.5.0 – 10.5.12 | — |
| github.com | mattermost_mattermost | >= 10.5.0+incompatible | — |
| github.com | mattermost_mattermost | 11.0.0 – 11.0.2 | — |
| github.com | mattermost_mattermost_server_v8 | 0 – 8.0.0-20251013062617-7977e7e6dae3 | — |
| mattermost | mattermost | 10.11.0 – 10.11.4 | — |
| mattermost | mattermost | 10.12.0 – 10.12.1 | — |
| mattermost | mattermost | 10.5.0 – 10.5.12 | — |
| mattermost | mattermost | 11.0.0 – 11.0.2 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.5 | 10.11.5 |
| mattermost | mattermost_server | >= 10.12.0 < 10.12.2 | 10.12.2 |
| mattermost | mattermost_server | >= 10.5.0 < 10.5.13 | 10.5.13 |
| mattermost | mattermost_server | >= 11.0.0 < 11.0.3 | 11.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost
osv·2025-12-02
CVE-2025-12756 Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: .
GHSA
Mattermost fails to validate user permissions when deleting comments in Boards
ghsa·2025-12-01
CVE-2025-12756 [MEDIUM] CWE-863 Mattermost fails to validate user permissions when deleting comments in Boards
Mattermost fails to validate user permissions when deleting comments in Boards
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
OSV
Mattermost fails to validate user permissions when deleting comments in Boards
osv·2025-12-01
CVE-2025-12756 [MEDIUM] Mattermost fails to validate user permissions when deleting comments in Boards
Mattermost fails to validate user permissions when deleting comments in Boards
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-01
Published