PT-2026-25757 · Mattermost · Mattermost+1
CVSS v3.1
3.5
Baixa
| Vetor | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mattermost versions 10.11.x through 10.11.10
Description
Mattermost does not properly validate a user's authentication method when processing an account authentication type switch. This allows an authenticated attacker to change an account password without confirmation by falsely claiming a different authentication provider. The issue is present in the
github.com/mattermost/mattermost-server module before version v5.3.2-0.20260127144908-ced9a56e3988.Recommendations
Update Mattermost to a version later than 10.11.10.
Update the
github.com/mattermost/mattermost-server module to version v5.3.2-0.20260127144908-ced9a56e3988 or later.Exploit
Correção
DoS
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mattermost
Github.Com/Mattermost/Mattermost-Server