CVE-2025-49810Incorrect Authorization in Mattermost Mattermost-server

Severity
4.3MEDIUMNVD
CNA3.5
EPSS
0.0%
top 91.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21
Latest updateAug 29

Description

Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDmattermost/mattermost_server10.5.010.5.9
Gogithub.com/mattermost_mattermost_server_v8< 8.0.0-20250721095846-c602a4a78e1f
CVEListV5mattermost/mattermost10.5.010.5.8

🔴Vulnerability Details

4
OSV
Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server2025-08-29
GHSA
Mattermost Lack of Access Control Validation2025-08-21
OSV
Mattermost Lack of Access Control Validation2025-08-21
CVEList
Thread summarization allows persistent access to channel2025-08-21
CVE-2025-49810 — Incorrect Authorization | cvebase