PT-2025-32579 · Mattermost · Mattermost Confluence Plugin

Lorenzo Gallegos

·

Published

2025-07-10

·

Updated

2025-08-20

·

CVE-2025-53910

CVSS v3.1

4.0

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Confluence Plugin versions prior to 1.5.0
Description: The Mattermost Confluence Plugin does not verify user access to a channel, enabling attackers to create channel subscriptions without authorization through an API call to the edit channel subscription endpoint /api/v1/channels/{channel id}/subscriptions/{user id}. The vulnerable parameter is user id.
Recommendations: Update Mattermost Confluence Plugin to version 1.5.0 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-09759
CVE-2025-53910
GHSA-V6C8-G53H-MC2H
GO-2025-3869
OPENSUSE-SU-2025:15469-1

Affected Products

Mattermost Confluence Plugin