cbcvebase.
CVE-2025-55070
published 2025-11-14

CVE-2025-55070: Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

Affected

5 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 11.1.011.1.0
github.commattermost_mattermost-server>= 0 < 11.1.0+incompatible11.1.0+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250912063506-7d8b7b5e4a608.0.0-20250912063506-7d8b7b5e4a60
mattermostmattermost<= <11
mattermostmattermost_server< 11.0.011.0.0