cbcvebase.
CVE-2025-9081
published 2025-09-19

CVE-2025-9081: Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration

Affected

10 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-plugin-boards>= 0 < 0.0.0-20250716054606-3f3e3becfe1d0.0.0-20250716054606-3f3e3becfe1d
github.commattermost_mattermost-server>= 10.5.0-rc1 < 10.5.910.5.9
github.commattermost_mattermost-server>= 10.5.0-rc1+incompatible < 10.5.9+incompatible10.5.9+incompatible
github.commattermost_mattermost-server>= 9.11.0-rc1 < 9.11.189.11.18
github.commattermost_mattermost-server>= 9.11.0-rc1+incompatible < 9.11.18+incompatible9.11.18+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250721095935-11c36f4d1e448.0.0-20250721095935-11c36f4d1e44
mattermostmattermost10.5.0 – 10.5.8
mattermostmattermost9.11.0 – 9.11.17
mattermostmattermost_server>= 10.5.0 < 10.5.910.5.9
mattermostmattermost_server>= 9.11.0 < 9.11.179.11.17