CVE-2025-13870
published 2025-12-02CVE-2025-13870: Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.20%
9.8th percentile
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost | >= 10.11.0 < 10.11.5 | 10.11.5 |
| github.com | mattermost_mattermost | >= 10.11.0+incompatible < 10.11.5+incompatible | 10.11.5+incompatible |
| github.com | mattermost_mattermost | >= 10.5.0 < 10.5.13 | 10.5.13 |
| github.com | mattermost_mattermost | >= 10.5.0+incompatible < 10.5.13+incompatible | 10.5.13+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20250905150616-ba86dfc5876b | 8.0.0-20250905150616-ba86dfc5876b |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20251212204551-54f2e9b4afd5 | 8.0.0-20251212204551-54f2e9b4afd5 |
| mattermost | mattermost | 10.11.0 – 10.11.4 | — |
| mattermost | mattermost | 10.5.0 – 10.5.12 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.5 | 10.11.5 |
| mattermost | mattermost_server | >= 10.5.0 < 10.5.13 | 10.5.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost
osv·2025-12-08
CVE-2025-13870 Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost
GHSA
Mattermost fails to validate user permissions in Boards
ghsa·2025-12-02
CVE-2025-13870 [LOW] CWE-284 Mattermost fails to validate user permissions in Boards
Mattermost fails to validate user permissions in Boards
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
OSV
Mattermost fails to validate user permissions in Boards
osv·2025-12-02
CVE-2025-13870 [LOW] Mattermost fails to validate user permissions in Boards
Mattermost fails to validate user permissions in Boards
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-02
Published