PT-2025-48544 · Mattermost · Mattermost

Daynight

·

Published

2025-10-28

·

Updated

2025-12-15

·

CVE-2025-12756

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 11.0.0 through 11.0.2 Mattermost versions 10.5.0 through 10.5.12 Mattermost versions 10.11.0 through 10.11.4 Mattermost versions 10.12.0 through 10.12.1
Description The software does not properly check user permissions when deleting comments within the Boards feature. This allows a user with editor role privileges to delete comments created by other users. The affected functionality involves the deletion of comments in Boards.
Recommendations Update Mattermost to a version later than 11.0.2. Update Mattermost to a version later than 10.12.1. Update Mattermost to a version later than 10.11.4. Update Mattermost to a version later than 10.5.12.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-15206
CVE-2025-12756
GHSA-P6GJ-JC38-X2M7
GO-2025-4172
SUSE-SU-2025:4395-1

Affected Products

Mattermost