CVE-2025-13870 — Missing Authentication for Critical Function in Mattermost Mattermost
Severity
4.3MEDIUMNVD
CNA3.1
EPSS
0.0%
top 85.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 2
Latest updateDec 8
Description
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
4OSV▶
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost↗2025-12-08