PT-2025-48657 · Mattermost · Mattermost

Doyensec

·

Published

2025-12-02

·

Updated

2026-01-06

·

CVE-2025-13870

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.5.x through 10.5.12 Mattermost versions 10.11.x through 10.11.4
Description An authenticated user can access files and subscribe to blocks in Boards without proper permission validation. This allows access to files from other boards and subscription to blocks from boards the user should not have access to.
Recommendations Update Mattermost to a version later than 10.5.12. Update Mattermost to a version later than 10.11.4.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-13870
GHSA-58W6-W55X-6WQ8
GO-2025-4178
SUSE-SU-2025:4395-1
SUSE-SU-2026:0037-1

Affected Products

Mattermost