CVE-2025-2527Incorrect Authorization in Mattermost Mattermost-server

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 61.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 15
Latest updateMay 23

Description

Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDmattermost/mattermost_server9.11.09.11.12+1
Gogithub.com/mattermost_mattermost-server9.11.0+incompatible9.11.12+incompatible+1
CVEListV5mattermost/mattermost10.5.010.5.2+1

🔴Vulnerability Details

4
OSV
Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server2025-05-23
OSV
Mattermost Fails to Verify User's Permissions When Accessing Groups2025-05-15
CVEList
Improper access control to group information2025-05-15
GHSA
Mattermost Fails to Verify User's Permissions When Accessing Groups2025-05-15
CVE-2025-2527 — Incorrect Authorization | cvebase