PT-2025-46947 · Mattermost · Mattermost

Published

2025-10-15

·

Updated

2025-11-17

·

CVE-2025-55070

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions prior to 11
Description Mattermost versions before 11 do not enforce multi-factor authentication on WebSocket connections. This allows unauthenticated users to access sensitive information through WebSocket events.
Recommendations Update to a version of Mattermost that is version 11 or later.

Fix

Improper Access Control

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-16015
CVE-2025-55070
GHSA-XPG8-8XPV-948P
GO-2025-4128

Affected Products

Mattermost