CVE-2025-13870Missing Authentication for Critical Function in Mattermost Mattermost

Severity
4.3MEDIUMNVD
CNA3.1
EPSS
0.0%
top 85.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 2
Latest updateDec 8

Description

Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDmattermost/mattermost_server10.5.010.5.13+1
Gogithub.com/mattermost_mattermost10.11.010.11.5+3
Gogithub.com/mattermost_mattermost_server_v8< 8.0.0-20250905150616-ba86dfc5876b+1
CVEListV5mattermost/mattermost10.11.010.11.4+1

🔴Vulnerability Details

4
OSV
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost2025-12-08
CVEList
Unauthorized access and subscription vulnerability in Boards2025-12-02
GHSA
Mattermost fails to validate user permissions in Boards2025-12-02
OSV
Mattermost fails to validate user permissions in Boards2025-12-02
CVE-2025-13870 — Mattermost Mattermost vulnerability | cvebase