User Permission Validation Flaw in Mattermost Product by Mattermost
CVE-2025-13870

3.1LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
2 December 2025

What is CVE-2025-13870?

Certain versions of Mattermost have a critical flaw that fails to adequately validate user permissions when accessing files and subscribing to blocks in Boards. This allows authenticated users to gain unauthorized access to files from other boards, as well as subscribe to blocks they do not have permission for. Users should ensure they are running the latest version to protect their data and maintain security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Mattermost 10.11.0 <= 10.11.4

Mattermost 10.5.0 <= 10.5.12

Mattermost 11.1.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Doyensec
.